Buffer Overflow Vulnerability in Microsoft SQL Server 2000 and MSDE
CVE-2000-1087
Currently unrated
Summary
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and the SQL Server Desktop Engine (MSDE) fails to properly limit buffer lengths. This oversight can lead to a denial of service or allow an attacker to execute arbitrary commands through the SQL Server API for Extended Stored Procedures (XP). By manipulating the parameter parsing in this way, attackers can exploit the vulnerability to disrupt service or gain unauthorized access.
References
EPSS Score
43% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved