Microsoft SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability( 11 February 2009 )
RISK: Medium Risk
A remote code execution vulnerability exists in the way that SQL Server checks parameters in the "sp_replwritetovarbin" extended stored procedure. The vulnerability could allow remote code execution if untrusted users have access to an affected system or if a SQL injection vulnerability exists on an affected system. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts.
Impact
- Remote Code Execution
System / Technologies affected
- Windows Server 2003
- Windows Server 2008
- Microsoft SQL Server 2000 Desktop Engine (WMSDE)
- Windows Internal Database (WYukon)
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
SQL Server
Windows Components
Microsoft SQL Server 2000 Desktop Engine (WMSDE) (KB960082) | Windows Internal Database (WYukon) Service Pack 2 (KB960089) |
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 | Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 |
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 | Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2 |
- | Windows Server 2008 for 32-bit Systems |
- | Windows Server 2008 for x64-based Systems |
Vulnerability Identifier
Source
Related Link
Share with