You are here: silicon.com > Software > Operating Systems

Operating Systems

SQL Server vulnerability warning from Microsoft

But no sign of active code attacks

Tags: server, microsoft, sql

By Steven Musil

Published: 23 December 2008 09:56 GMT

Microsoft has issued an advisory confirming a remote code execution vulnerability affecting its SQL Server line.

The vulnerability affects Microsoft SQL Server 2000, Microsoft SQL Server 2005, Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2000 Desktop Engine (WMSDE), and Windows Internal Database (WYukon). Microsoft said systems with Microsoft SQL Server 7.0 Service Pack 4, Microsoft SQL Server 2005 Service Pack 3, and Microsoft SQL Server 2008 are not affected by this issue.

Microsoft's advisory said: "Microsoft is aware that exploit code has been published on the internet for the vulnerability addressed by this advisory. Our investigation of this exploit code has verified that it does not affect systems that have had the workarounds listed below applied. Currently, Microsoft is not aware of active attacks that use this exploit code or of customer impact at this time."

"In addition, due to the mitigating factors for default installations of MSDE 2000 and SQL Server 2005 Express, Microsoft is not currently aware of any third-party applications that use MSDE 2000 or SQL Server 2005 Express which would be vulnerable to remote attack. However, Microsoft is actively monitoring this situation to provide customer guidance as necessary."

Microsoft said it was unaware of any active attacks utilising the exploit code.

The advisory comes less than a week after Microsoft released a critical security patch to plug vulnerabilities in Internet Explorer amid malicious attackers taking advantage of the security flaws.

Original article: Microsoft warns of SQL Server vulnerability from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

for IT White Papers Newsletter

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Database Administrator

By submitting your CV, you give express consent to us using your details for this purpose. You should have an in-depth knowledge of SQL Server ...

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH)

You must have previous experience in a dedicated vulnerability management function where you have been responsible for all potential attacks on a ...

Windows, .NET Implementation Support Engineer

Work with the development team to deliver final solutions into the production environment Liaise with the development team to resolve any problems ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: