microsoft
Report a problem

Microsoft confirms new SQL server threat

TajByte   on 24 December 2008 - 01:12 · 9 comments & 4763 views

Advertisement (Why?)
Microsoft has confirmed the existence of a new and potentially serious security threat to users of its SQL Server database software.

"Microsoft is aware that exploit code has been published on the Internet for the vulnerability addressed by this advisory," the company said in a bulletin published Monday.

The threat is essentially software code that hackers could use to access or alter corporate databases built with SQL Server. The malicious code could allow what's known in IT security as remote code execution, a process by which hackers could, for instance, alter figures in a bank account without ever setting foot on the bank's premises.

News source: Information Week

Post a comment · Send to friend Comments · There are 9 additional comments
(2 replies) #1 vetmarkjensen on 24 Dec 2008 - 01:24
From Secunia: http://secunia.com/Advisories/33034/
Privilege escalation, From local network

So it would be from a trusted/authenticated user who either is malicious or is 'socially engineered' into running exploit code.

Needs to get patched, as it is important, but at least this isn't remotely and anonymously executable.
#1.1 GP007 on 24 Dec 2008 - 01:49
It technically is patched, as the above says:

"The threat does not affect SQL Server 7.0 Service Pack 4, SQL Server 2005 Service Pack 3, or SQL Server 2008, Microsoft said. "

So just upgrade to the newest SQL version (200 or to the newest service pack.
#1.2 Jelly2003 on 24 Dec 2008 - 02:09
GP007 said,
It technically is patched, as the above says:

"The threat does not affect SQL Server 7.0 Service Pack 4, SQL Server 2005 Service Pack 3, or SQL Server 2008, Microsoft said. "

So just upgrade to the newest SQL version (200 or to the newest service pack.

Yeah, just remember that users are often idiots

I've seen a case of a product written for someone where they log in using SQL server credentials and the only login it accepts is 'SA'
#2 skynetXrules on 24 Dec 2008 - 01:28
The threat is essentially software code that hackers could use to access or alter corporate databases built with SQL Server. The malicious code could allow what's known in IT security as remote code execution, a process by which hackers could, for instance, alter figures in a bank account without ever setting foot on the bank's premises

that sounds good if it is your own acc muhahahha !
#3 Antaris on 24 Dec 2008 - 01:59
Lol, SQL Server is nearly rock solid, not often a security vulnerability crops up, like IIS. If only all products Microsoft released where this solid!
#4 SolwayUK on 24 Dec 2008 - 13:09
alter figures in a bank account without ever setting foot on the bank's premises


just a couple of more 0's on the end
#5 vetneufuse on 24 Dec 2008 - 13:26
SQL Server is a very secure service.. good to see they already fixed the bug before it really got out there
#6 Sawyer12 on 24 Dec 2008 - 15:07
alter figures in a bank account without ever setting foot on the bank's premises Thats rather funny!
#7 _dandy_ on 24 Dec 2008 - 16:27
> alter figures in a bank account without ever setting foot on the bank's premises.

Yeah, because typically, banks will have their database machines directly accessible off their web site...

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)