NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


SQL Server 2008 Safe from Critical Vulnerability Affecting the Microsoft Data Platform

PoC (Proof of Concept) code available in the wild

By Marius Oiaga, Technology News Editor

23rd of December 2008, 19:34 GMT

Adjust text size:


SQL Server 2008
Enlarge picture
The latest iteration of SQL Server is safe from a critical vulnerability affecting the Microsoft data platform. In addition to SQL Server 2008, the software giant revealed that SQL Server 7.0 SP4, and SQL Server 2005 SP3 are also not impacted in the least by the security flaw which could allow for remote code execution in the eventuality of a successful exploit. Bill Sisk, Microsoft Security Response Center Communications Manager, pointed out that Proof of Concept code had already been published in the wild, but emphasized that Microsoft had not detected any attack targeting the vulnerability.

“To successfully exploit this vulnerability an attacker must be local, or remote, authenticated user on the system. However, if an attacker has already compromised a web server via SQL injection, they could exploit this vulnerability as an unauthenticated user,” Sisk stated.

Microsoft has not yet provided a security update designed to patch the vulnerability. Still, the company is offering affected customers a workaround designed to bulletproof their data platforms against exploits. The workaround involves denying permissions on the sp_replwritetovarbin extended stored procedure, according to the Redmond company, which has published an advisory on the matter, that you can access via this link.

Among the vulnerable solutions, the company enumerated SQL Server 2000, SQL Server 2005, SQL Server 2005 Express Edition, SQL Server 2000 Desktop Engine (MSDE 2000), SQL Server 2000 Desktop Engine (WMSDE), and Windows Internal Database (Wyukon).

“It’s important to note that systems with Microsoft SQL Server 7.0 Service Pack 4, Microsoft SQL Server 2005 SP3 and Microsoft SQL Server 2008 are not affected by this issue. Also, because, by default, Microsoft SQL Server Desktop Engine 2000 (MSDE 2000) and SQL Server 2005 Express do not allow remote connections, attackers would have to already have local access to machines running MSDE 2000 and SQL Server 2005 Express to exploit this vulnerability,” Sisk added.

Microsoft has already released an out-of-band security update this month, aiming to plug a security hole in all supported versions of Internet Explorer, including IE8 Beta 2 on Windows Vista SP1 and Windows XP SP3, as well as IE8 Beta on Windows pre-beta.

TAGS:

SQL Server 2008 | vulnerability | patch | security update
Read by 1,458 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Download 2 Free SQL Server 2008 Releases

Download Windows 7 Web Platform Installer Release Candidate (RC)

Microsoft Dynamics NAV 2009 Generally Available from December 1

Microsoft Applauds 1.1 Petabytes SQL Server 2008 Database

Download Microsoft Assessment and Planning Toolkit 3.2 RTM

Download UrlScan 3.1

‘Don’t Believe the Hype About Open Source - It’s Seductive, but Misleading’

Free Office Accounting 2009 Upgrades

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM