CVE-1999-1011
published 1999-07-19CVE-1999-1011: The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
77.14%
99.5th percentile
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | data_access_components | — | — |
| microsoft | data_access_components | — | — |
| microsoft | data_access_components | — | — |
| microsoft | index_server | — | — |
| microsoft | internet_information_server | — | — |
| microsoft | internet_information_server | — | — |
| microsoft | site_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests targeting the RDS DataFactory endpoint at /msadc/msadcs.dll on IIS servers; any remote POST to this path should be treated as suspicious exploitation activity. ↗
- →Monitor for VbBusObj or AdvancedDataFactory method invocations via RDS requests, which are alternative exploitation techniques used to inject shell commands. ↗
- →Alert on shell() VBA command usage originating from IIS/MDAC processes, which indicates exploitation of the JET OLE DB Provider to execute OS commands with SYSTEM privileges. ↗
- →Look for creation of or access to known MDB files (e.g., btcustmr.mdb, advworks.mdb, eecustmr.mdb) by IIS worker processes, which indicates active RDS exploitation attempts. ↗
- →Detect creation of tables named 'AZZ' in Access MDB files accessible via IIS, which is a leftover artifact from v1 of the msadc.pl exploit. ↗
- →Monitor for queries against MSysModules table via ODBC/JET from IIS processes, which is the primary exploitation query used in msadc.pl v2. ↗
- →Detect UNC path references (e.g., \\server\share\file.mdb) in ODBC/RDS requests from IIS, which indicates UNC-based exploitation to load remote MDB files. ↗
- →Monitor for well-known DSN names (wicca, AdvWorks, pubs, CertSvr, ADCDemo, ADCTest, etc.) being probed via RDS/ODBC requests, which are dictionary-guessed by the exploit script. ↗
- ·Newer releases of msadcs.dll deny remote RDS connections by default, so the vulnerability may not be exploitable even if the DLL is present. ↗
- ·The exploit script reports 'Success!' when a valid SQL statement is issued, NOT when the shell command actually executed — MDAC 2.1+ silently ignores shell commands, causing false positives. ↗
- ·VbBusObj exploitation provides poor error reporting and is prone to both false positives and false negatives; verify VbBusObj availability with -N (NetBIOS name query) before relying on detections based on this method. ↗
- ·RDS can be excluded from a default NT 4.0 Option Pack installation via custom install, so presence of IIS does not guarantee the vulnerable endpoint exists. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (2)
exploitdb·1999-07-19
CVE-1999-1011 Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (2)
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (2)
---
source: https://www.securityfocus.com/bid/529/info
MDAC (Microsoft Data Access Components) is a package used to integrate web and database services. It includes a component named RDS (Remote Data Services). RDS allows remote access via the internet to database objects through IIS. Both are included in a default installation of the Windows NT 4.0 Option Pack, but can be excluded via a custom installation.
RDS includes a component called the DataFactory object, which has a vulnerability that could allow any web user to:
--Obtain unauthorized access to unpublished files on the IIS server
--Use MDAC to tunnel ODBC requests thr
Exploit-DB
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (1)
exploitdb·1999-07-19
CVE-1999-1011 Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (1)
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (1)
---
source: https://www.securityfocus.com/bid/529/info
MDAC (Microsoft Data Access Components) is a package used to integrate web and database services. It includes a component named RDS (Remote Data Services). RDS allows remote access via the internet to database objects through IIS. Both are included in a default installation of the Windows NT 4.0 Option Pack, but can be excluded via a custom installation.
RDS includes a component called the DataFactory object, which has a vulnerability that could allow any web user to:
--Obtain unauthorized access to unpublished files on the IIS server
--Use MDAC to tunnel ODBC requests thr
Exploit-DB
UNICOS 9/MAX 1.3/mk 1.5 / AIX 4.2 / libc 5.2.18 / RedHat 4 / IRIX 6 / Slackware 3 - NLS (1)
exploitdb·1997-02-13
CVE-1999-0041 UNICOS 9/MAX 1.3/mk 1.5 / AIX 4.2 / libc 5.2.18 / RedHat 4 / IRIX 6 / Slackware 3 - NLS (1)
UNICOS 9/MAX 1.3/mk 1.5 / AIX 4.2 / libc 5.2.18 / RedHat 4 / IRIX 6 / Slackware 3 - NLS (1)
---
/*
source: https://www.securityfocus.com/bid/711/info
Cray UNICOS 9.0/9.2/MAX 1.3/mk 1.5,AIX */
"\x24\x02\x03\xf3" /* li $v0,1011 */
"\x23\xff\x01\x14" /* addi $ra,$ra,276 */
"\x23\xe4\xff\x08" /* addi $a0,$ra,-248 */
"\x23\xe5\xff\x10" /* addi $a1,$ra,-240 */
"\xaf\xe4\xff\x10" /* sw $a0,-240($ra) */
"\xaf\xe0\xff\x14" /* sw $zero,-236($ra) */
"\xa3\xe0\xff\x0f" /* sb $zero,-241($ra) */
"\x03\xff\xff\xcc" /* syscall */
"/bin/sh"
;
char jump[]=
"\x03\xa0\x10\x25" /* move $v0,$sp */
"\x03\xe0\x00\x08" /* jr $ra */
;
char nop[]="\x24\x0f\x12\x34";
main(int argc,char **argv){
char buffer[10000],adr[4],tmp[4],*b,*envp[2];
int i,n=-1;
printf("copyright LAST STAGE OF DELIRIUM sep 1997 poland //
Metasploit
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
metasploit
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
This module can be used to execute arbitrary commands on IIS servers that expose the /msadc/msadcs.dll Microsoft Data Access Components (MDAC) Remote Data Service (RDS) DataFactory service using VbBusObj or AdvancedDataFactory to inject shell commands into Microsoft Access databases (MDBs), MSSQL databases and ODBC/JET Data Source Name (DSN). Based on the msadcs.pl v2 exploit by Rain.Forest.Puppy, which was actively used in the wild in the late Ninties. MDAC versions affected include MDAC 1.5, 2.0, 2.0 SDK, 2.1 and systems with the MDAC Sample Pages for RDS installed, and NT4 Servers with the NT Option Pack installed or upgraded 2000 systems often running IIS3/4/5 however some vulnerable installations can still
http://www.ciac.org/ciac/bulletins/j-054.shtmlhttp://www.osvdb.org/272https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025https://www.securityfocus.com/bid/529http://www.ciac.org/ciac/bulletins/j-054.shtmlhttp://www.osvdb.org/272https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025https://www.securityfocus.com/bid/529
1999-07-19
Published