Microsoft JET Database Engine RCE Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The vulnerability lies with the management of indexes in the JET database engine that, if exploited successfully, can cause an out-of-bounds memory write. This can lead to remote code execution at the privilege level of the current process. To exploit this vulnerability an attacker would require the targeted user to open a specially crafted malicious file that calls a JET database source via a Microsoft component known as an Object Linking and Embedding Database (OLEDB).
The researcher from Trend Micro who discovered the vulnerability has published a proof of concept after giving 120 days notice to Microsoft for the opportunity to develop an update, which means that 0-day attacks are possible at the time of publication.
Threat updates
| Date | Update |
|---|---|
| 15 Oct 2018 |
The vulnerability has now been identified as CVE-2018-8423. This only affects 32-bit versions of the affected platforms. The 'msrd3x40.dll' binary is the vulnerable component in Windows JET Database Engine |
Remediation steps
| Type | Step |
|---|---|
|
At the time of publication there is no confirmation of when an update that addresses this vulnerability will be released. To prevent and detect a trojan infection, ensure that:
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:48 pm