Buffer Overflow in Microsoft SQL Server 2000 and MSDE
CVE-2000-1088

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
9 January 2001

Summary

The vulnerability in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) arises from improper buffer length restrictions in the xp_SetSQLSecurity function. This oversight allows attackers to exploit the srv_paraminfo function within the SQL Server API for Extended Stored Procedures. As a result, this can lead to a denial of service or enable the execution of arbitrary commands on the affected system, potentially compromising its integrity.

References

EPSS Score

25% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2000-1088 : Buffer Overflow in Microsoft SQL Server 2000 and MSDE | SecurityVulnerability.io