Get a Pentest and security assessment of your IT network.

Advisories

Atstake Security Advisory 03-07-08.1

Atstake Security Advisory A070803-1 – By specifying the name of a named pipe instead of a file, as an argument to Microsoft SQL Server’s xp_fileexist extended stored procedure, one can impersonate the user account Microsoft SQL Server is running under. This is due to the behavior of the CreateFile system call and Windows named pipe impersonation. This is not limited to Microsoft SQL Server, but a system wide problem.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31337/a070803-1.txt

Source: https://packetstormsecurity.com/files/31337/Atstake-Security-Advisory-03-07-08.1.html

Related posts
Advisories

dsa-622.txt

Advisories

Secunia Security Advisory 17623

Advisories

Secunia Security Advisory 20395

Advisories

Secunia Security Advisory 23316