CVE-2008-5416
HIGH 9.0EPSS 87.0%
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and Windows Internal Database (WYukon) SP2 allows remote authenticated users to cause a denial of service (access violation exception) or execute arbitrary code by calling the sp_replwritetovarbin extended stored procedure with a set of invalid parameters that trigger memory overwrite, aka "SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability."
- CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 87.04% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2008-12-10
- Updated
- 2024-08-07
Proof-of-concept exploits (1)
- SECFORCE/CVE-2008-54163★ · 2017-05-03
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/16396
- https://www.exploit-db.com/exploits/16392
- https://www.exploit-db.com/exploits/7501