vendor:
Microsoft SQL Server
by:
securma massine
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Microsoft SQL Server
Affected Version From: MSSQL7.0 sp0
Affected Version To: MSSQL7.0 sp3
Patch Exists: YES
Related CWE:
CPE: a:microsoft:mssql_server:7.0
Platforms Tested: Windows
2000
Microsoft mssql 7.0 server denial of service vulnerability
By sending a large buffer with specified data, an attacker can stop the Microsoft mssql 7.0 server. The error noticed is different according to the services' pack, but the result is always the same. Exception Codes = c0000005. This code is for educational purposes and the author is not responsible for any acts performed using this exploit.
Mitigation:
Apply the latest service pack or patch provided by Microsoft to address this vulnerability. Additionally, restrict network access to the affected server and monitor for any unusual activity.