MS.SQL.Server.Insert.Statements.Privilege.Elevation

description-logoDescription

This indicates an attack attempt to exploit a privilege elevation vulnerability in Microsoft SQL Server.
The vulnerability is caused by the lack of checks when the vulnerable software handles insert statements. It allows a remote attacker to execute arbitrary code by sending some crafted SQL expressions.

affected-products-logoAffected Products

SQL Server 2005 SP1 and SQL Server 2005 SP2
SQL Server 2005 x64-based Edition SP1 and SQL Server 2005 x64-based Edition SP2
SQL Server 2005 for Itanium-based Systems and SQL Server 2005 SP1 and SP2
Microsoft SQL Server 2005 Express Edition SP1 and SP2
Microsoft SQL Server 2005 Express Edition with Advanced Services SP1 and SP2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply patch, available from the web site:
http://www.microsoft.com/technet/security/Bulletin/ms08-040.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)