MS KB870669: ADODB.Stream object from Internet Explorer

High Nessus Plugin ID 12298


The remote host contains a version of IE which may read and write to local files.


The remote host contains a vulnerability in IE. The ADODB.Stream object can be used by a malicious web page to read and write to local files.

An attacker could use this flaw to gain access to the data on the remote host. To exploit this flaw, an attacker would need to set up a rogue website and lure a user on the remote host into visiting it. If the website contains the proper call to the ADODB object, then it may execute data on the remote host.


Microsoft produced a workaround for this problem.

See Also

Plugin Details

Severity: High

ID: 12298

File Name: smb_nt_kb870669.nasl

Version: $Revision: 1.24 $

Type: local

Agent: windows

Family: Windows

Published: 2004/07/06

Modified: 2017/08/30

Dependencies: 13855

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:ie

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2003/09/11

Reference Information

BID: 10514

OSVDB: 7915

MSKB: 870669