CVE-1999-0999: Input Validation
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft SQL Server 7.0from your environment.If Microsoft SQL Server 7.0 is not required, uninstall or decommission affected instances to eliminate exposure to the vulnerability.
- Compensating control
Restrict network exposure of Microsoft SQL Server instances and block or filter TDS (Tabular Data Stream) traffic at the network perimeter or firewall to prevent delivery of malformed TDS packets from untrusted networks.
- Operational
Monitor Microsoft security advisories for an official patch or update that addresses the malformed TDS packet denial-of-service and apply the vendor-supplied fix when it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0999?
CVE-1999-0999 is classified as a denial of service vulnerability affecting Microsoft SQL Server 7.0.
How do I fix CVE-1999-0999?
To fix CVE-1999-0999, it is recommended to apply any available patches or updates provided by Microsoft.
What systems are affected by CVE-1999-0999?
CVE-1999-0999 specifically affects Microsoft SQL Server version 7.0.
Can CVE-1999-0999 be exploited remotely?
Yes, CVE-1999-0999 can be exploited remotely through malformed TDS packets.
What type of attack does CVE-1999-0999 enable?
CVE-1999-0999 enables remote attackers to cause a denial of service attack on the affected SQL servers.