CVE-2002-0649
EXPLOITEDMicrosoft Data Engine - Memory Corruption
Title source: ruleDescription
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16393
exploitdb
WORKING POC
VERIFIED
by David Litchfield · c++remotewindows
https://www.exploit-db.com/exploits/21652
metasploit
WORKING POC
GOOD
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mssql/ms02_039_slammer.rb
References (23)
... and 3 more
Scores
EPSS
0.8581
EPSS Percentile
99.4%
Details
VulnCheck KEV
2003-08-01
CWE
CWE-119
Status
published
Products (2)
microsoft/data_engine
2000
microsoft/sql_server
2000 (3 CPE variants)
Published
Aug 12, 2002
Tracked Since
Feb 18, 2026