Buffer Overflow Vulnerability in Microsoft SQL Server and MSDE
CVE-2000-1082

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 January 2001

What is CVE-2000-1082?

The vulnerability exists in the xp_enumresultset function within Microsoft SQL Server and the Microsoft SQL Server Desktop Engine (MSDE). It fails to properly manage the buffer length prior to invoking the srv_paraminfo function call in the SQL Server API for Extended Stored Procedures. Exploiting this flaw allows attackers to adversely affect system availability or execute unauthorized commands, posing a significant threat to applications reliant on the server.

References

EPSS Score

43% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.