A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges.
An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website.
The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 20 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory, aka 'ActiveX Data Objects (ADO) Remote Code Execution Vulnerability'. | A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website. The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory. | 
| Title | ActiveX Data Objects (ADO) Remote Code Execution Vulnerability | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: microsoft
Published: 2019-06-12T13:49:38
Updated: 2025-05-20T17:49:26.389Z
Reserved: 2018-11-26T00:00:00
Link: CVE-2019-0888
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2019-06-12T14:29:01.337
Modified: 2025-05-20T18:15:29.123
Link: CVE-2019-0888
 Redhat
                        Redhat
                    No data.