CVE-2006-5559: Input Validation

Published Oct 27, 2006
·
Updated

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

Affected Software

21 affected components
Microsoft Windows 2000=sp4
Microsoft Data Access Components=2.5-sp3
Microsoft Windows XP=sp2
Microsoft Data Access Components=2.8-sp1
Microsoft Windows 2003 Server
Microsoft Windows 2003 Server=itanium
Microsoft Data Access Components=2.8
Microsoft Data Access Components=2.7-sp1
All of the following
Microsoft Windows 2000=sp4
Microsoft Data Access Components=2.5-sp3
All of the following
Microsoft Windows XP=sp2
Microsoft Data Access Components=2.8-sp1
All of the following
Any of the following
Microsoft Windows 2003 Server
Microsoft Windows 2003 Server=itanium
Microsoft Data Access Components=2.8
All of the following
Microsoft Windows 2000=sp4
Microsoft Data Access Components=2.7-sp1
All of the following
Microsoft Windows 2000=sp4
Microsoft Data Access Components=2.8
All of the following
Microsoft Windows 2000=sp4
Microsoft Data Access Components=2.8-sp1

Event History

Oct 27, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
04:07 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·04:07 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2006-5559?

CVE-2006-5559 is considered a critical vulnerability due to its potential for remote code execution.

2

How do I fix CVE-2006-5559?

To fix CVE-2006-5559, you should apply the latest security patches and updates for Microsoft Data Access Components.

3

Which versions of software are affected by CVE-2006-5559?

CVE-2006-5559 affects Microsoft Data Access Components 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1.

4

What can exploit CVE-2006-5559?

CVE-2006-5559 can be exploited via maliciously crafted input sent to the ADODB.Connection object.

5

Is my system safe from CVE-2006-5559 if I use updated Windows versions?

If you are using updated versions of Windows that are not reliant on the vulnerable versions of Microsoft Data Access Components, your system is safer from CVE-2006-5559.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203