Security hole found in Microsoft's SQL Server
More toil for the already over-worked Microsoft security team, as SQL Server is the latest product be hit by issues.
Microsoft has warned about another critical vulnerability, this time affecting SQL Server.
The company said that it is investigating reports of a vulnerability which allows remote code execution on systems with versions of Microsoft SQL Server 2000, 2005, 2005 Express Edition, 2000 Desktop Engine, 2000 Desktop Engine, and Windows Internal Database (WYukon).
It added that systems with newer versions, such as Microsoft SQL Server 7.0 Service Pack 4, 2005 Service Pack 3, and Server 2008, were not affected by this issue.
Exploit code has already been published on the internet for the vulnerability, but Microsoft says that it won't have any affect if workarounds listed in its advisory are followed.
The software giant also said that it was currently unaware of any attacks which were using the exploit code.
The advisory stated: "Upon completion of the investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs."
Microsoft stated that the vulnerability could not be exposed anonymously. An attacker would need to authenticate to exploit the vulnerability, or take advantage of a SQL injection vulnerability in a web application that is able to authenticate.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The warning comes only a week after a huge security hole in Internet Explorer was patched up.
-
RSAC Conference 2025: The front line of cyber innovation
ITPro Podcast Ransomware, quantum computing, and an unsurprising focus on AI were highlights of this year's event
-
Anthropic CEO Dario Amodei thinks we're burying our heads in the sand on AI job losses
News With AI set to hit entry-level jobs especially, some industry execs say clear warning signs are being ignored
-
Hackers are targeting Ivanti VPN users again – here’s what you need to know
News Ivanti has re-patched a security flaw in its Connect Secure VPN appliances that's been exploited by a China-linked espionage group since at least the middle of March.
-
Broadcom issues urgent alert over three VMware zero-days
News The firm says it has information to suggest all three are being exploited in the wild
-
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claim
News Over 200 vulnerable Nakivo backup instances have been identified months after the firm silently patched a security flaw.
-
Everything you need to know about the Microsoft Power Pages vulnerability
News A severe Microsoft Power Pages vulnerability has been fixed after cyber criminals were found to have been exploiting unpatched systems in the wild.
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
-
A critical Ivanti flaw is being exploited in the wild – here’s what you need to know
News Cyber criminals are actively exploiting a critical RCE flaw affecting Ivanti Connect Secure appliances
-
Researchers claim an AMD security flaw could let hackers access encrypted data
News Using only a $10 test rig, researchers were able to pull off the badRAM attack
-
A journey to cyber resilience
whitepaper DORA: Ushering in a new era of cyber security