Buffer Overflow in Microsoft SQL Server 2000 and MSDE
CVE-2000-1088
Currently unrated
What is CVE-2000-1088?
The vulnerability in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) arises from improper buffer length restrictions in the xp_SetSQLSecurity function. This oversight allows attackers to exploit the srv_paraminfo function within the SQL Server API for Extended Stored Procedures. As a result, this can lead to a denial of service or enable the execution of arbitrary commands on the affected system, potentially compromising its integrity.