← Vulnerability feed

Vulnerability record · CVE-2002-0649 · published 12 August 2002

CVE-2002-0649: Microsoft SQL Server 2000 Resolution Service UDP buffer overflow

Microsoft · Data Engine

The SQL Server 2000 and MSDE Resolution Service contains multiple buffer overflows reachable over UDP port 1434. A 0x04 byte can force the SQL Monitor thread to build an oversized registry key name, and a 0x08 byte with a long string causes heap corruption. The flaw is remotely reachable without authentication and was the vector for the Slammer/Sapphire worm.

7.5 CVSS 2.0 High EPSS 85% · top 0.3% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
46References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution over UDP with a documented worm history and very high EPSS probability warrants critical priority despite the absence of a KEV listing.

What it is

The SQL Server 2000 and MSDE Resolution Service contains multiple buffer overflows reachable over UDP port 1434. A 0x04 byte can force the SQL Monitor thread to build an oversized registry key name, and a 0x08 byte with a long string causes heap corruption. The flaw is remotely reachable without authentication and was the vector for the Slammer/Sapphire worm.

Impact

An unauthenticated remote attacker can crash the service for denial of service or execute arbitrary code in the SQL Server process context. Successful code execution typically yields system-level control of the database host.

Attack surface

Reached by sending crafted UDP packets to port 1434 on an exposed SQL Server 2000 or MSDE instance; no authentication or user interaction is required per the network vector AV:N/AC:L/Au:N.

Exploitation

The description states the flaw was exploited by the Slammer/Sapphire worm, and EPSS is 0.8475 (99.7th percentile), though CISA KEV does not list it and reference tags carry no exploit labels.

What to do

  • Apply Microsoft security bulletin MS02-039 to patch the Resolution Service buffer overflows.
  • Block or restrict inbound UDP port 1434 at network perimeters and host firewalls.
  • Disable or remove the SQL Server Resolution Service where it is not required.
  • Isolate or retire unsupported SQL Server 2000 and MSDE installations that cannot be patched.
  • Monitor for and filter UDP 1434 traffic to prevent worm-style propagation.

Detection

  • Alert on inbound UDP traffic to port 1434 from untrusted networks.
  • Monitor SQL Server and MSDE processes for unexpected crashes or restarts.
  • Watch for anomalous registry key creation activity by the SQL Monitor thread.
  • Use network signatures for the 0x04 and 0x08 payload patterns described in the advisory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=102760196931518&w=2
http://marc.info/?l=ntbugtraq&m=102760479902411&w=2
http://secunia.com/advisories/7945 Vendor Advisory
http://www.cert.org/advisories/CA-2002-22.html US Government Resource
http://www.cert.org/advisories/CA-2003-04.html US Government Resource
http://www.kb.cert.org/vuls/id/399260 US Government Resource
http://www.kb.cert.org/vuls/id/484891 US Government Resource
http://www.securityfocus.com/archive/1/308306/30/26180/threaded
http://www.securityfocus.com/archive/1/308321/30/26180/threaded
http://www.securityfocus.com/archive/1/308324/30/26180/threaded
http://www.securityfocus.com/archive/1/308388/30/26180/threaded
http://www.securityfocus.com/archive/1/308393/30/26180/threaded
http://www.securityfocus.com/archive/1/308396/30/26150/threaded
http://www.securityfocus.com/archive/1/308418/30/26150/threaded
http://www.securityfocus.com/archive/1/308419/30/26150/threaded
http://www.securityfocus.com/archive/1/308760/30/26120/threaded
http://www.securityfocus.com/archive/1/308806/30/26120/threaded
http://www.securityfocus.com/archive/1/309096/30/26120/threaded
http://www.securityfocus.com/archive/1/309324/30/26120/threaded
http://www.securityfocus.com/archive/1/309776/30/26090/threaded
http://www.securityfocus.com/bid/5310
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-039
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1077
http://marc.info/?l=bugtraq&m=102760196931518&w=2
http://marc.info/?l=ntbugtraq&m=102760479902411&w=2
http://secunia.com/advisories/7945 Vendor Advisory
http://www.cert.org/advisories/CA-2002-22.html US Government Resource
http://www.cert.org/advisories/CA-2003-04.html US Government Resource
http://www.kb.cert.org/vuls/id/399260 US Government Resource
http://www.kb.cert.org/vuls/id/484891 US Government Resource
http://www.securityfocus.com/archive/1/308306/30/26180/threaded
http://www.securityfocus.com/archive/1/308321/30/26180/threaded
http://www.securityfocus.com/archive/1/308324/30/26180/threaded
http://www.securityfocus.com/archive/1/308388/30/26180/threaded
http://www.securityfocus.com/archive/1/308393/30/26180/threaded
http://www.securityfocus.com/archive/1/308396/30/26150/threaded
http://www.securityfocus.com/archive/1/308418/30/26150/threaded
http://www.securityfocus.com/archive/1/308419/30/26150/threaded
http://www.securityfocus.com/archive/1/308760/30/26120/threaded
http://www.securityfocus.com/archive/1/308806/30/26120/threaded

Track CVE-2002-0649 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0618Microsoft SQL Server Reporting Services ViewState deserialization RCESQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can…KEVEPSS 99%analysed8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed10.0CVE-2000-1209Microsoft SQL Server and MSDE default null sa passwordMicrosoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumble…EPSS 87%analysed9.8CVE-2018-8273Microsoft sql server out-of-bounds write vulnerabilityA buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…EPSS 29%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2002-0649), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.