« Volver al listado

CVE-2008-0086

Estado: ModificadaAlta (9)—

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0086",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-08T23:41:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/30970",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/494082/100/0/threaded",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1020441",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
      "tags": [
        "US Government Resource"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2022/references",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14052",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://secunia.com/advisories/30970",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/494082/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/516397/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1020441",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2011-0003.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2022/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-040",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14052",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression."
    },
    {
      "lang": "es",
      "value": "Un desbordamiento de búfer en la función convert en SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4 y 2000 Desktop Engine (WMSDE), de Microsoft, permite a usuarios autenticados remotos ejecutar código arbitrario por medio de una expresión SQL diseñada."
    }
  ],
  "lastModified": "2026-06-16T22:48:54.730",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:data_engine:1.0:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12788D78-4334-4A8A-9841-3DD894FDED50"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54EB3111-B93A-4577-9592-0D13FE7FD2C4"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server:2000:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7A5116E-BD37-4539-B815-F1B70EC4D45D"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server:2005:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26423C70-4475-4D7E-8CC0-D8CFADE16B26"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server_desktop_engine:2000:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7910EDCF-376B-462A-996D-782C27E7322A"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server_express_edition:2005:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E9E6FCD-B64C-4BA5-BD11-5659B61D74BD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}