Home > Sql Server > SQL Server 2000 Utilities Vulnerability: July 24

SQL Server 2000 Utilities Vulnerability: July 24

* WINDOWS & .NET MAGAZINE ONLINE FORUMS http://www.winnetmag.com/forums Featured Thread: Recovery Console Password Recovery (One message in this thread) Kris So named by Christopher J. Dl_ddladmin members can execute & administer Data Definition Language statements on a database, thereby allowing them to create tables and views, but they don't have any broader privileges on the database Would the vulnerability enable the attacker to gain control over the entire machine?

Issue The patch below eliminates two newly discovered vulnerabilities affecting SQL Server 2000 and MSDE 2000: A buffer overrun vulnerability that occurs in several Database Consistency Checkers (DBCCs) that ship as

One of the stored procedures can only be executed by users who either are database administrators or are members of the db_owner fixed database role.

  • While many of these are executable only by sysadmin, some are executable by members of the db_owner and db_ddladmin roles as well.
  • There is a direct connection between versions of MSDE and versions of SQL Server.
  • The vulnerability is subject to two important constraints: Neither of the stored procedures affected by the vulnerability should be accessible to unprivileged users, if best practices have been followed.
Have you used a product that changed your IT experience by saving you time or easing your daily burden?

The vulnerability results because two stored procedures in SQL Server 2000 associated with replication are vulnerable to SQL injection attacks. In the most serious case, exploiting this vulnerability would enable an attacker to run code in the context of the SQL Server service, thereby giving the attacker complete control over all

However, applying this patch is not sufficient by itself to fully secure a SQL Server 2000 server: One security fix for SQL Server 2000, discussed in Microsoft Security Bulletin MS02-035, requires By default, this account is disabled.

The patch does not supersede any previously released patches for MDAC or OLAP under SQL Server 2000. If the attacker used the vulnerability to cause the SQL Server service to fail, what would be needed in order to restore normal operation?

In most cases, a db_owner or db_ddladmin would already have domain user privileges, so the vulnerability wouldn't provide a way to gain operating system privileges. Does this vulnerability affect SQL Server 7.0?

VERSIONS AFFECTED   Microsoft SQL Server 2000 Microsoft Desktop Engine (MSDE) 2000   DESCRIPTION   Two vulnerabilities exist in Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000.

I thought the db_owner and db_ddladmin roles already had administrative privileges.

But following these steps is the only way I know to download the software for free.

Who could exploit this vulnerability? By the way, the prescriptive architecture guides included with Accelerator provide great value as standalone guides. Microsoft is a plumbing company.

This philosophy is 100 percent accurate. Finally, I selected "Dynamically determine port" rather than entering 15000 as the port number. If the account had been enabled, the vulnerability could enable an attacker who could execute either of the two stored procedures to carry out a SQL Injection attack and run either

