vendor:
SQL Server
by:
refdom
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SQL Server
Affected Version From: Microsoft SQL Server 2000
Affected Version To: Microsoft SQL Server 2000
Patch Exists: YES
Related CWE: CVE-2003-0542
CPE: a:microsoft:sql_server:2000
Metasploit:
https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2003-0542/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-cve-2003-0542/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-1_3_x-local-configuration-regular-expression-overflow-cve-2003-0542/, https://www.rapid7.com/db/vulnerabilities/http-apache-mod-regex-bof/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2003
Microsoft SQL Server Denial of Service Vulnerability
Microsoft SQL Server and the Microsoft Data Engine have been reported prone to a denial of service attack. Any local or remote user, who can authenticate and is part of the Everyone Group, may trigger a denial of service condition in an affected SQL Server. It has been reported that, if a remote attacker sends an unusually large request to a named pipe, the SQL Server will become unresponsive.
Mitigation:
Microsoft has released a patch to address this issue. Users are advised to apply the appropriate patch.