Security hole found in Microsoft's SQL Server
More toil for the already over-worked Microsoft security team, as SQL Server is the latest product be hit by issues.
Microsoft has warned about another critical vulnerability, this time affecting SQL Server.
The company said that it is investigating reports of a vulnerability which allows remote code execution on systems with versions of Microsoft SQL Server 2000, 2005, 2005 Express Edition, 2000 Desktop Engine, 2000 Desktop Engine, and Windows Internal Database (WYukon).
It added that systems with newer versions, such as Microsoft SQL Server 7.0 Service Pack 4, 2005 Service Pack 3, and Server 2008, were not affected by this issue.
Exploit code has already been published on the internet for the vulnerability, but Microsoft says that it won't have any affect if workarounds listed in its advisory are followed.
The software giant also said that it was currently unaware of any attacks which were using the exploit code.
The advisory stated: "Upon completion of the investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs."
Microsoft stated that the vulnerability could not be exposed anonymously. An attacker would need to authenticate to exploit the vulnerability, or take advantage of a SQL injection vulnerability in a web application that is able to authenticate.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The warning comes only a week after a huge security hole in Internet Explorer was patched up.
-
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
-
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
-
Critical Dell Storage Manager flaws could let hackers access sensitive data – patch nowNews A trio of flaws in Dell Storage Manager has prompted a customer alert
-
Flaw in Lenovo’s customer service AI chatbot could let hackers run malicious code, breach networksNews Hackers abusing the Lenovo flaw could inject malicious code with just a single prompt
-
Industry welcomes the NCSC’s new Vulnerability Research Initiative – but does it go far enough?News The cybersecurity agency will work with external researchers to uncover potential security holes in hardware and software
-
Hackers are targeting Ivanti VPN users again – here’s what you need to knowNews Ivanti has re-patched a security flaw in its Connect Secure VPN appliances that's been exploited by a China-linked espionage group since at least the middle of March.
-
Broadcom issues urgent alert over three VMware zero-daysNews The firm says it has information to suggest all three are being exploited in the wild
-
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claimNews Over 200 vulnerable Nakivo backup instances have been identified months after the firm silently patched a security flaw.
-
Everything you need to know about the Microsoft Power Pages vulnerabilityNews A severe Microsoft Power Pages vulnerability has been fixed after cyber criminals were found to have been exploiting unpatched systems in the wild.
-
Vulnerability management complexity is leaving enterprises at serious riskNews Fragmented data and siloed processes mean remediation is taking too long