CVE-2006-5559: Input Validation
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5559?
CVE-2006-5559 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-5559?
To fix CVE-2006-5559, you should apply the latest security patches and updates for Microsoft Data Access Components.
Which versions of software are affected by CVE-2006-5559?
CVE-2006-5559 affects Microsoft Data Access Components 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1.
What can exploit CVE-2006-5559?
CVE-2006-5559 can be exploited via maliciously crafted input sent to the ADODB.Connection object.
Is my system safe from CVE-2006-5559 if I use updated Windows versions?
If you are using updated versions of Windows that are not reliant on the vulnerable versions of Microsoft Data Access Components, your system is safer from CVE-2006-5559.