Buffer Overflow Vulnerability in Microsoft SQL Server Products
CVE-2000-1081

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 January 2001

What is CVE-2000-1081?

The xp_displayparamstmt function within SQL Server and Microsoft SQL Server Desktop Engine (MSDE) is susceptible to a buffer overflow due to inadequate restrictions on buffer length before invoking the srv_paraminfo function in the API for Extended Stored Procedures. This flaw can be exploited by attackers to create a denial of service condition or execute arbitrary commands, potentially leading to severe disruptions or unauthorized actions within the database environment.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.