Back
CVE-2000-1086
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
Published: Jan 9, 2001
Modified: Apr 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| microsoft | data_engine | 1.0 |
| microsoft | data_engine | 2000 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 2000 |
GitHub Security Advisory GHSA-mf6v-4fxg-pwvj
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE)...
References (6)
- http://marc.info/?l=bugtraq&m=97570884410184&w=2
- http://www.securityfocus.com/bid/2041 Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092
- http://marc.info/?l=bugtraq&m=97570884410184&w=2
- http://www.securityfocus.com/bid/2041 Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092
Risk Scores
CVSS Score
4.6 / 10
EPSS Score
43.15%
Top 2% most likely to be exploited
Threat Score
31.3 / 100
Data Sources
NVD
EPSS
GitHub