Zero Day Initiative disclosed unpatched Microsoft Jet database flaw

All supported versions of Windows affected by remote code execution bug

Microsoft Jet database interface

Security researchers have disclosed a remote code execution vulnerability that affects the Microsoft Jet Database Engine.

According to a blog post by the Zero Day Initiative (ZDI), an out-of-bounds (OOB) write in the Microsoft JET Database Engine that could allow remote code execution was initially reported to Microsoft back in May. Microsoft managed to reproduce the bug shortly afterwards.

While Microsoft has patched two other buffer overflow bugs in Jet in its latest Patch Tuesday update, this bug has been left out and will be fully patched in the October update.

"An attacker could leverage this vulnerability to execute code under the context of the current process, however it does require user interaction since the target would need to open a malicious file. As of today, this bug remains unpatched," said Simon Zuckerbraun, a security researcher at ZDI.

The bug affects all supported Windows versions including server editions. The flaw itself can be triggered by opening a Jet source via a Microsoft component known as Object Linking and Embedding Database (OLEDB).

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"To trigger this vulnerability, a user would need to open a specially crafted file containing data stored in the JET database format. Various applications use this database format. An attacker using this would be able to execute code at the level of the current process," said Zuckerbraun.

In a security advisory, ZDI said the issue is in Microsoft Jet's index manager. "Crafted data in a database file can trigger a write past the end of an allocated buffer," stated the advisory.

The advisory said that given the nature of the vulnerability "the only salient mitigation strategy is to restrict interaction with the application to trusted files".

A proof-of-concept exploit code has been posted on GitHub.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Most Popular

Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020