Secunia Logo  


Secunia PSI WorldMap
 
MS-SQL 2000 Worm propagating
Secunia Advisory: SA7945
Release Date: 2003-01-25
Last Update: 2004-04-01
Popularity: 12,501 views

Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:Microsoft Access 2000
Microsoft Access 2002
Microsoft Office Project 2002
Microsoft Project 2000
Microsoft Project Central Server
Microsoft Project Professional 2002
Microsoft Project Server 2002
Microsoft SQL Server 2000
Microsoft SQL Server 2000 Desktop Engine (MSDE 2000)
Microsoft Visual FoxPro 8.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Only systems that allow access to port 1434/udp can be infected by this worm.

Other Microsoft SQL ports:
ms-sql-s 1433/tcp #Microsoft-SQL-Server
ms-sql-s 1433/udp #Microsoft-SQL-Server
ms-sql-m 1434/tcp #Microsoft-SQL-Monitor
ms-sql-m 1434/udp #Microsoft-SQL-Monitor

The vulnerability was closed by Microsoft in July 2002:
http://www.microsoft.com/technet/security/bulletin/ms02-039.asp
We recommend that you use MS02-061 instead as it is newer and closes other issues too:
http://www.microsoft.com/technet/security/bulletin/MS02-061.asp
The updates are also included in Microsoft SQL Server 2000 Servicepack 3.
NOTE: that if you have applied hotfix Q317748, which is a bug fix from Microsoft, after the above patches, then your system will still be vulnerable, as this hotfix introduce an old version of ssnetlib.dll

The worm does not harm the system it affects and can be removed by rebooting the system as it only resides in memory.

Any system that has been infected by this worm should be considered compromised as it has been exposed to a known vulnerability for so long. We recommend that you reinstall.

Changelog:
26/01-2003 Added information about MSDE 2000 and other software using MSDE 2000.
27/01-2003 Added link to official Microsoft advisory regarding slammer
01/04-2004 Added CVE reference

Other References:
http://www.sarc.com/avcenter/venc/data/w32.sqlexp.worm.html
http://www.nextgenss.com/advisories/mssql-udp.txt
http://www.digitaloffense.net/worms/mssql_udp_worm/
http://isc.incidents.org/
http://www.microsoft.com/technet/security/virus/alerts/slammer.asp

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

27th Nov, 2009
New advisories: 8
New vulnerabilities: 15
Updated advisories: 11

Moderately // 349 views
Ubuntu update for php5

26th Nov, 2009
New advisories: 15
New vulnerabilities: 37
Updated advisories: 48

Moderately // 509 views
SugarCRM Multiple Vulnerabilities

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 39 views
2. Oracle Database Multiple Vulnerabilities // 27 views
3. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 22 views
4. Adobe Flash Player Multiple Vulnerabilities // 17 views
5. Internet Explorer Layout Handling Memory Corruption Vulnerability // 14 views
6. Adobe Reader/Acrobat Multiple Vulnerabilities // 14 views
7. php Download Manager "content" File Inclusion Vulnerability // 12 views
8. Firefox infoRSS Extension Cross-Context Scripting Vulnerability // 10 views
9. Robo-FTP Response Processing Buffer Overflow Vulnerability // 10 views
10. Mozilla Firefox Multiple Vulnerabilities // 10 views