Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution (CVE-1999-1011)

  Severity: CRITICAL
  CVE Identifier: CVE-1999-1011

  DESCRIPTION

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000608
  Trend Micro Deep Security DPI Rule Name: 1000608 - Generic SQL Injection Prevention

  AFFECTED SOFTWARE AND VERSION

  • Microsoft IIS 3.0
  • Microsoft IIS 4.0
  • Microsoft Index Server 2.0
  • Microsoft MDAC 1.5
  • Microsoft MDAC 2.0
  • Microsoft MDAC 2.1 CLEAN
  • Microsoft MDAC 2.1 UPGRADE
  • Microsoft Site Server 3.0