. Microsoft SQL Server 2000 64 bit all editions
. Microsoft SQL Server 2000 all editions SP3
. Microsoft SQL Server 2000 all editions SP3a
. Microsoft SQL Server 7.0 Service Pack 4
. Microsoft SQL Server 2000 Desktop Engine MSDE SP3
. Microsoft Data Engine MSDE 1.0
. Microsoft Data Engine MSDE 1.0 SP4
Microsoft SQL Server 7, 2000, and MSDE allows:
- local users go gain privileges by hijacking a named pipe during the authentication of another user, i.e the "Named Pipe Hijacking" vulnerability
- local or remote authenticated users to cause a "Denial of service" crash or hang via a long request to a named pipe
- local users to execute arbitrary code via a certain request to the Local Procedure Calls LPC port that leads to a "Buffer overflow."