CVE-2000-1087: Medium severity Microsoft SQL Server vulnerability
The xpproxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srvparaminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1087?
CVE-2000-1087 is considered to be of low severity, primarily causing denial of service.
How do I fix CVE-2000-1087?
To fix CVE-2000-1087, apply the latest security updates and patches provided by Microsoft for SQL Server and MSDE.
What versions are affected by CVE-2000-1087?
CVE-2000-1087 affects Microsoft SQL Server 2000, Microsoft SQL Server 7.0, and Microsoft Data Engine versions 1.0 and 2000.
What type of attack does CVE-2000-1087 facilitate?
CVE-2000-1087 allows attackers to exploit a buffer overflow to potentially cause a denial of service.
Is CVE-2000-1087 still a threat today?
While CVE-2000-1087 is an old vulnerability, it may still be a threat if affected systems have not been patched or upgraded.