CVE-2006-5559 describes a critical denial-of-service and potential arbitrary code execution vulnerability in the ADODB.Connection ActiveX control within Microsoft Data Access Components (MDAC) versions 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1, affecting Windows 2000, 2003 Server, and XP. This flaw, rated with a CVSS score of 9.3, stems from improper memory tracking when the Execute method is called with specific BSTR arguments, allowing remote attackers to crash Internet Explorer and potentially execute malicious code. While there is no evidence of active exploitation or KEV listing, a proof-of-concept exploit exists on ExploitDB, and it has a high FAUCET Risk Score of 99/100, indicating significant potential impact despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5CPE matchmatch criteria | cpe:2.3:a:microsoft:data_access_components:2.5:sp3:*:*:*:*:*:* | ||
2.8CPE matchmatch criteria | cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:* | ||
2.8CPE matchmatch criteria | cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:* | ||
2.7CPE matchmatch criteria | cpe:2.3:a:microsoft:data_access_components:2.7:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.