News

Microsoft Releases SQL Bug Warning

Microsoft has released a patch that eliminates a security vulnerability in SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0. The vulnerability could allow a remote author of a malicious SQL query to take unauthorized actions on a SQL Server or MSDE database or on the underlying system that was hosting the SQL Server or MSDE database.

Microsoft (www.microsoft.com) SQL Server 7.0 and MSDE 1.0 perform incomplete argument validation on certain classes of remotely submitted SQL statements. If a user is able to submit a particular form of a SQL Select statement to SQL Server or MSDE, it is possible to take actions on the SQL database or, if the SQL Server or MSDE is operating in an account with elevated privileges on the underlying system, or the underlying operating system itself.

In order to exploit this vulnerability, a user would have to have the right to submit queries to the SQL Server or MSDE via ODBC, OLE DB, or DB-Library and be logged on using SQL Server Security. The user would not require any special privileges beyond the right to submit SQL queries.

Microsoft SQL Server 7.0 and MSDE 1.0 are affected by the vulnerability. A patch is available at http://www.microsoft.com/downloads/release.asp?ReleaseID=19132. - Isaac Slepner

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Microsoft Offers Support Extensions for Exchange 2016 and 2019

    Microsoft has introduced a paid Extended Security Update (ESU) program for on-premises Exchange Server 2016 and 2019, offering a crucial safety cushion as both versions near their Oct. 14, 2025 end-of-support date.

  • An image of planes flying around a globe

    2025 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • Notebook

    Microsoft Centers AI, Security and Partner Dogfooding at MCAPS

    Microsoft's second annual MCAPS for Partners event took place Tuesday, delivering a volley of updates and directives for its partners for fiscal 2026.

  • Microsoft Layoffs: AI Is the Obvious Elephant in the Room

    As Microsoft doubles down on an $80 billion bet on AI this fiscal year, its workforce reductions are drawing scrutiny over whether AI's ascent is quietly reshaping its human capital strategy, even as official messaging avoids drawing a direct line.