CVE-2012-1891: Microsoft Data Access Components
Critical severity, CVSS 9.8. EPSS: 29.4% chance of exploitation in the next 30 days.
Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
Affected products
- Microsoft Data Access Components: version 2.8 only
- Microsoft Windows Data Access Components: version 6.0 only
Published 2012-07-10. Last modified 2026-06-16.