Vulnerability record · CVE-2002-0649 · published 12 August 2002
CVE-2002-0649: Microsoft SQL Server 2000 Resolution Service UDP buffer overflow
Microsoft · Data Engine
The SQL Server 2000 and MSDE Resolution Service contains multiple buffer overflows reachable over UDP port 1434. A 0x04 byte can force the SQL Monitor thread to build an oversized registry key name, and a 0x08 byte with a long string causes heap corruption. The flaw is remotely reachable without authentication and was the vector for the Slammer/Sapphire worm.
Description
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution over UDP with a documented worm history and very high EPSS probability warrants critical priority despite the absence of a KEV listing.
What it is
The SQL Server 2000 and MSDE Resolution Service contains multiple buffer overflows reachable over UDP port 1434. A 0x04 byte can force the SQL Monitor thread to build an oversized registry key name, and a 0x08 byte with a long string causes heap corruption. The flaw is remotely reachable without authentication and was the vector for the Slammer/Sapphire worm.
Impact
An unauthenticated remote attacker can crash the service for denial of service or execute arbitrary code in the SQL Server process context. Successful code execution typically yields system-level control of the database host.
Attack surface
Reached by sending crafted UDP packets to port 1434 on an exposed SQL Server 2000 or MSDE instance; no authentication or user interaction is required per the network vector AV:N/AC:L/Au:N.
Exploitation
The description states the flaw was exploited by the Slammer/Sapphire worm, and EPSS is 0.8475 (99.7th percentile), though CISA KEV does not list it and reference tags carry no exploit labels.
What to do
- Apply Microsoft security bulletin MS02-039 to patch the Resolution Service buffer overflows.
- Block or restrict inbound UDP port 1434 at network perimeters and host firewalls.
- Disable or remove the SQL Server Resolution Service where it is not required.
- Isolate or retire unsupported SQL Server 2000 and MSDE installations that cannot be patched.
- Monitor for and filter UDP 1434 traffic to prevent worm-style propagation.
Detection
- Alert on inbound UDP traffic to port 1434 from untrusted networks.
- Monitor SQL Server and MSDE processes for unexpected crashes or restarts.
- Watch for anomalous registry key creation activity by the SQL Monitor thread.
- Use network signatures for the 0x04 and 0x08 payload patterns described in the advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0649 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0649), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.