Get a Pentest and security assessment of your IT network.

Advisories

Atstake Security Advisory 03-07-23.3

Atstake Security Advisory A072303-3 – By sending a specially crafted message to the local LPC port for Microsoft SQL Server, it is possible to overwrite information stored on the stack. This would allow an attacker to execute code under SQL Server’s credentials thereby escalating privileges. This would then allow the user to read and write access to the database files. If the SQL Server is running under the Administrator or Local System account this would enable system compromise.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31429/a072303-3.txt

Source: https://packetstormsecurity.com/files/31429/Atstake-Security-Advisory-03-07-23.3.html

Related posts
Advisories

Secunia Security Advisory 15661

Advisories

Secunia Security Advisory 18729

Advisories

Debian Linux Security Advisory 1144-1

Advisories

Mandriva Linux Security Advisory 2007.062