vendor:
Data Access Components
by:
SecurityFocus
7.5
CVSS
HIGH
Remote Data Services vulnerability
264
CWE
Product Name: Data Access Components
Affected Version From: Windows NT 4.0 Option Pack
Affected Version To: Windows 98
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 98, Windows NT
2002
RDS Exploit information
The vulnerability allows any web user to obtain unauthorized access to unpublished files on the IIS server and use MDAC to tunnel ODBC requests through to a remote internal or external location, thereby obtaining access to non-public servers or effectively masking the source of an attack on another network.
Mitigation:
Disable RDS if not needed, or restrict access to the RDS service.