Security hole found in Microsoft's SQL Server
By Asavin Wattanajantra,
Microsoft has warned about another critical vulnerability, this time affecting SQL Server.
The company said that it is investigating reports of a vulnerability which allows remote code execution on systems with versions of Microsoft SQL Server 2000, 2005, 2005 Express Edition, 2000 Desktop Engine, 2000 Desktop Engine, and Windows Internal Database (WYukon).
It added that systems with newer versions, such as Microsoft SQL Server 7.0 Service Pack 4, 2005 Service Pack 3, and Server 2008, were not affected by this issue.
Exploit code has already been published on the internet for the vulnerability, but Microsoft says that it won't have any affect if workarounds listed in its advisory are followed.
The software giant also said that it was currently unaware of any attacks which were using the exploit code.
The advisory stated: “Upon completion of the investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs.”
Microsoft stated that the vulnerability could not be exposed anonymously. An attacker would need to authenticate to exploit the vulnerability, or take advantage of a SQL injection vulnerability in a web application that is able to authenticate.
The warning comes only a week after a huge security hole in Internet Explorer was patched up.
You may also like...
advertisement
Latest Security Features
Q&A: The ID card commissioner talks cards and controversy
We spoke to ID card commissioner Sir John Pilling about his thoughts on the identity scheme and why we might all think he's a bit of prat down the line.
- So you've been hacked, now what?
- The problems facing Internet Explorer
- Year in Review: 2009 in your words
- Top 10 security predictions for 2010
- Year in Review: Top tech stories of 2009
- The worst IT disasters of 2009
- Five free security software suites
- How to stay safe shopping online
- Is it time to switch to IPv6?
Latest Security Reviews
Symantec Backup Exec 2010 review
Rating: ![]()
advertisement
Most popular
- Your Views: Google Street View across the UK
- Reviews round-up: Windows Phone 7 and Firefox Mobile
- Q&A: Conrad Wolfram on communicating with apps in Web 3.0
- Why is Microsoft accelerating Service Pack 1?
- Palm 'disapointed' by results, Pre sales
- Google updates Chrome, awards security bonus
- Report: Macs cost less to run than Windows PCs
- A guide to BlackBerry Messenger 5.0
- Windows Phone 7 review ? hands on
- HTC Legend review
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




