An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website.
The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 20 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft windows 10 1507
Microsoft windows 10 1607 Microsoft windows 10 1809 Microsoft windows Server 1803 Microsoft windows Server 1903 Microsoft windows Server 2008 R2 Microsoft windows Server 2008 Sp2 Microsoft windows Server 2012 R2 |
|
| CPEs | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_1803:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:* cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:itanium:* cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft windows 10 1507
Microsoft windows 10 1607 Microsoft windows 10 1809 Microsoft windows Server 1803 Microsoft windows Server 1903 Microsoft windows Server 2008 R2 Microsoft windows Server 2008 Sp2 Microsoft windows Server 2012 R2 |
Tue, 20 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory, aka 'ActiveX Data Objects (ADO) Remote Code Execution Vulnerability'. | A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website. The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory. |
| Title | ActiveX Data Objects (ADO) Remote Code Execution Vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-05-20T17:49:26.389Z
Reserved: 2018-11-26T00:00:00.000Z
Link: CVE-2019-0888
No data.
Status : Modified
Published: 2019-06-12T14:29:01.337
Modified: 2025-05-20T18:15:29.123
Link: CVE-2019-0888
No data.
OpenCVE Enrichment
No data.