Vulnerability record · CVE-2008-5416 · published 10 December 2008
CVE-2008-5416: Microsoft SQL Server sp_replwritetovarbin heap buffer overflow
Microsoft · Sql Server
A heap-based buffer overflow exists in the sp_replwritetovarbin extended stored procedure in Microsoft SQL Server 2000, MSDE 2000, SQL Server 2005 SP2, WMSDE and Windows Internal Database. Calling the procedure with a crafted set of invalid parameters overwrites memory, allowing a remote authenticated user to crash the service or execute arbitrary code. The flaw matters because the procedure is reachable through normal database connections and the affected platforms were widely deployed.
Description
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and Windows Internal Database (WYukon) SP2 allows remote authenticated users to cause a denial of service (access violation exception) or execute arbitrary code by calling the sp_replwritetovarbin extended stored procedure with a set of invalid parameters that trigger memory overwrite, aka "SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability."
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote authenticated code execution with a complete confidentiality, integrity and availability impact and has public exploit code, but it requires valid credentials and affects legacy SQL Server versions.
What it is
A heap-based buffer overflow exists in the sp_replwritetovarbin extended stored procedure in Microsoft SQL Server 2000, MSDE 2000, SQL Server 2005 SP2, WMSDE and Windows Internal Database. Calling the procedure with a crafted set of invalid parameters overwrites memory, allowing a remote authenticated user to crash the service or execute arbitrary code. The flaw matters because the procedure is reachable through normal database connections and the affected platforms were widely deployed.
Impact
An attacker with valid database credentials gains the ability to cause a denial of service via an access violation, or to run arbitrary code in the context of the SQL Server service account. Successful code execution typically yields full control of the database host.
Attack surface
Reached over the network through the SQL Server TDS interface by invoking the sp_replwritetovarbin extended stored procedure; the CVSS vector (AV:N/AC:L/Au:S) indicates low complexity but requires a valid authenticated session. No user interaction is needed beyond issuing the procedure call.
Exploitation
Public exploit code is referenced (Exploit-DB 7501 and an Exploit-tagged advisory), and EPSS is very high at 0.87 (99.7th percentile), though the CVE is not listed in CISA KEV. No ransomware group usage is documented.
What to do
- Apply Microsoft security bulletin MS09-004, which addresses this vulnerability, and retire or isolate unsupported SQL Server 2000/MSDE installations.
- Restrict EXECUTE permission on sp_replwritetovarbin and other extended stored procedures to only the accounts that genuinely require it.
- Enforce least privilege on SQL logins and avoid shared or application-wide accounts with broad database rights.
- Block direct SQL Server access from untrusted networks and require access through controlled, monitored paths.
Detection
- Alert on execution of sp_replwritetovarbin, especially with unusual or malformed parameter sets, via SQL Server audit or extended events.
- Monitor SQL Server error logs and Windows event logs for access violation exceptions or unexpected service crashes.
- Hunt for suspicious child processes spawned by sqlservr.exe, which would indicate post-exploitation code execution.
- Baseline normal use of replication-related extended stored procedures and flag deviations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-5416 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-5416), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.