Microsoft Jet Engine - '.MDB' File Parsing Stack Overflow
Author: cocoruder
type: local
platform: windows
port:
date_added: 2007-11-15
date_updated: 2017-07-14
verified: 1
codes: CVE-2007-6026
tags:
aliases: 11162007-Microsoft_Jet_Engine_MDB_File_Parsing_Exploit.rar
screenshot_url:
application_url:
Microsoft Jet Engine MDB File Parsing Stack Overflow Vulnerability
by cocoruder(frankruder_at_hotmail.com)
http://ruder.cdut.net
Summary:
A remote code execute vulnerability exists in Microsoft Jet
Engine. A remote attacker who successfully exploit this vulnerability
can execute arbitrary code on the affected system.
Affected Software Versions:
Microsoft Office Access 2003 sp3 on Windows XP SP2(chinese)
(Other versions may also be affected)
How to Reproduce:
Open the attached file
"Microsoft_Jet_Engine_MDB_File_Parsing_Exploit.mdb" with Office Access
2003 sp3 on Windows XP SP2, then "calc.exe" will be executed, please
do not use the exploit for attacking.
The attached file is at:
http://ruder.cdut.net/attach/MS_MDB_Vul/Microsoft_Jet_Engine_MDB_File_Parsing_Exploit.rar
Exploit-DB Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/4625.rar (11162007-Microsoft_Jet_Engine_MDB_File_Parsing_Exploit.rar)
MD5 Hash:73243B8823C8DC2C88AE0529CA13C4C6
# milw0rm.com [2007-11-16]