Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection Against Microsoft Data Access Components (MDAC) Function Vulnerability (MS06-014)

Subscribe

Check Point Reference: CPAI-2006-043
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS06-014
Industry Reference(s):

CVE-2006-0003

Protection Provided by: VPN-1
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55W
  • NG with Application Intelligence R55
VSX
  • NGX
InterSpect
  • NGX
  • 2.0 and 1.x
Who is Vulnerable?
  • Microsoft Windows XP SP1 running MDAC 2.7 SP1
  • Microsoft Windows XP SP2 running MDAC 2.8 SP1
  • Microsoft Windows XP Professional x64 Edition running MDAC SP2
  • Microsoft Windows Server 2003 running MDAC 2.8
  • Microsoft Windows Server 2003 SP1 running MDAC 2.8 SP2
Vulnerability Description
The Microsoft Data Access Components (MDAC) provides a number of supporting technologies for accessing and using databases. A vulnerability exists in a functionality distributed in MDAC which could be exploited be remote attackers to take complete control of an affected system.
Update/Patch Available
Apply patches:
Microsoft Security Bulletin MS06-014
Vulnerability Details
The vulnerability specifically exists in the RDS.Dataspace ActiveX control that is provided as part of the ActiveX Data Objects (ADO) and that is distributed in MDAC. RDS can be used to move data from a server to a client application or to a Web page, to manipulate the data on the client, and to return updates to the server in a single round trip. This flaw is due to an error in the "RDS.Dataspace" ActiveX control that fails to validate that it interacts safely when it is hosted on a Web page.

Protection Overview
The update protects against the MDAC vulnerability by blocking the vulnerable ActiveX control. Depending on the traffic mix, activating this protection may result in performance degradation.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
The update from May 21, 2006 includes the following protections:

Vulnerability in Microsoft Data Access Components (MDAC) Function (MS06-014) - CPAI-2006-043
Internet Explorer mhtml Redirection Vulnerability - CPAI-2006-044
Winny P2P Remote Buffer Overflow Vulnerability - CPAI-2006-045
IMAP Multiple Vulnerabilities - CPAI-2006-046
Enhanced Protection against Microsoft FrontPage XSS Vulnerability (MS06-017) - CPAI-2006-035
MYSQL Protections - CPSA-2006-04 (InterSpect NGX only)
Exclusion List for HTTP Client Protections

VPN-1 NGX R61

How Can I Protect My Network?
1. Update SmartDefense: Click the SmartDefense Services tab, In the left pane from the drop-down list, click Download Updates and then click the Online Update button.
2. In the Web Intelligence tree, click HTTP Client Protections > Microsoft Internet Explorer.
3. In the Microsoft Internet Explorer configuration pane, select

Block RDS.Dataspace MDAC Function Vulnerability (MS06-014)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?

SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Microsoft Internet Explorer - RDS.Dataspace MDAC Function Vulnerability (MS06-014)

VPN-1 NGX R60, VPN-1 NG with Application Intelligence R55W

How Can I Protect My Network?
1. Update SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the Web Intelligence tree, click HTTP Client Protections > Microsoft Internet Explorer.
3. In the Microsoft Internet Explorer configuration pane, click

Block RDS.Dataspace MDAC Function Vulnerability (MS06-014)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?

SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Microsoft Internet Explorer - RDS.Dataspace MDAC Function Vulnerability (MS06-014)

VPN-1 NG with Application Intelligence R55

How Can I Protect My Network?

1. Update SmartDefense by clicking Update Now in the SmartDashboard General window.
2. In the SmartDefense tree, click Application Intelligence > Web > HTTP Client Protections and then click Microsoft Internet Explorer.

 
3. In the Microsoft Internet Explorer configuration page, select

Block RDS.Dataspace MDAC Function Vulnerability (MS06-014)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?

Rule #99813 will appear on the SmartView Tracker.

VPN-1 VSX NGX

How Can I Protect My Network?
1. Update SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the Web Intelligence tree, click HTTP Client Protections > Microsoft Internet Explorer.
3. In the Microsoft Internet Explorer configuration pane, click

Block RDS.Dataspace MDAC Function Vulnerability (MS06-014)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log rule #99813.

InterSpect NGX

How Can I Protect My Network?

1. Update SmartDefense: In the left pane from the drop-down list, select Profiles > SmartDefense Service and click the Online Update button; In the left pane, select Profiles > Default Protection and select the Web Intelligence page of the profile.
2. In the Web Intelligence tree, click HTTP Client Protections > Microsoft Internet Explorer.
3. In the Microsoft Internet Explorer configuration pane, select

Block RDS.Dataspace MDAC Function Vulnerability (MS06-014)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?

SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Microsoft Internet Explorer - RDS.Dataspace MDAC Function Vulnerability (MS06-014)

InterSpect 2.0

How Can I Protect My Network?

1. Update SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the SmartDefense tree, click Application Intelligence > Web > HTTP Client Protections and then click Microsoft Internet Explorer.

3. In the Microsoft Internet Explorer, select

Block RDS.Dataspace MDAC Function Vulnerability (MS06-014)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?

SmartView Tracker will log the following entries:

Attack Name: Web Client Enforcement Violation
Attack Information: Microsoft Internet Explorer - RDS.Dataspace MDAC Function Vulnerability (MS06-014)