Buffer Overflow Vulnerability in Microsoft SQL Server 2000 and MSDE
CVE-2000-1087

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 January 2001

Summary

The xp_proxiedmetadata function in Microsoft SQL Server 2000 and the SQL Server Desktop Engine (MSDE) fails to properly limit buffer lengths. This oversight can lead to a denial of service or allow an attacker to execute arbitrary commands through the SQL Server API for Extended Stored Procedures (XP). By manipulating the parameter parsing in this way, attackers can exploit the vulnerability to disrupt service or gain unauthorized access.

References

EPSS Score

43% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2000-1087 : Buffer Overflow Vulnerability in Microsoft SQL Server 2000 and MSDE | SecurityVulnerability.io