CVE-2008-0107

Microsoft SQL Server 7.0-2005 SP2 Authenticated RCE via Crafted Backup File

Title source: llm
STIX 2.1

Description

Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."

References (13)

Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020441
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=723
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30970
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30119
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13936
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2022/references
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/494082/100/0/threaded
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-190A.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516397/100/0/threaded

Scores

EPSS 0.3454
EPSS Percentile 98.3%

Details

CWE
CWE-189
Status published
Products (8)
microsoft/data_engine 1.0 sp4
microsoft/sql_server 7.0 sp4
microsoft/sql_server 2000 sp4 (2 CPE variants)
microsoft/sql_server 2005 sp1 (8 CPE variants)
microsoft/sql_server_desktop_engine 2000 sp4
microsoft/windows_server_2008 (2 CPE variants)
microsoft/wmsde 2000
microsoft/wyukon (2 CPE variants)
Published Jul 08, 2008
Tracked Since Feb 18, 2026