vendor:
SQL Server Distributed Management Objects
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: SQL Server Distributed Management Objects
Affected Version From: 08.05.2004
Affected Version To: 08.05.2004
Patch Exists: NO
Related CWE: Unknown
CPE: microsoft:sql_server_distributed_management_objects
Platforms Tested:
2007
Microsoft SQL Server Distributed Management Objects OLE DLL Remote Buffer Overflow
The exploit involves passing fuzzy characters to the Start method of the SQL Server Distributed Management Objects OLE DLL (sqldmo.dll). By manipulating the EDX register, the first exploitable condition is achieved. Additionally, the Structured Exception Handler (SEH) is overwritten to gain control of the program flow. This vulnerability can be exploited if the ActiveX control is set to 'ask' or 'enabled' for the Internet zone.
Mitigation:
Apply the necessary patches and updates provided by Microsoft. Avoid executing untrusted code or opening untrusted files.