← Vulnerability feed

Vulnerability record · CVE-2008-5416 · published 10 December 2008

CVE-2008-5416: Microsoft SQL Server sp_replwritetovarbin heap buffer overflow

Microsoft · Sql Server

A heap-based buffer overflow exists in the sp_replwritetovarbin extended stored procedure in Microsoft SQL Server 2000, MSDE 2000, SQL Server 2005 SP2, WMSDE and Windows Internal Database. Calling the procedure with a crafted set of invalid parameters overwrites memory, allowing a remote authenticated user to crash the service or execute arbitrary code. The flaw matters because the procedure is reachable through normal database connections and the affected platforms were widely deployed.

9.0 CVSS 2.0 High EPSS 87% · top 0.3% CWE-119 · Memory buffer overflow
9.0CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
44References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and Windows Internal Database (WYukon) SP2 allows remote authenticated users to cause a denial of service (access violation exception) or execute arbitrary code by calling the sp_replwritetovarbin extended stored procedure with a set of invalid parameters that trigger memory overwrite, aka "SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability."

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows remote authenticated code execution with a complete confidentiality, integrity and availability impact and has public exploit code, but it requires valid credentials and affects legacy SQL Server versions.

What it is

A heap-based buffer overflow exists in the sp_replwritetovarbin extended stored procedure in Microsoft SQL Server 2000, MSDE 2000, SQL Server 2005 SP2, WMSDE and Windows Internal Database. Calling the procedure with a crafted set of invalid parameters overwrites memory, allowing a remote authenticated user to crash the service or execute arbitrary code. The flaw matters because the procedure is reachable through normal database connections and the affected platforms were widely deployed.

Impact

An attacker with valid database credentials gains the ability to cause a denial of service via an access violation, or to run arbitrary code in the context of the SQL Server service account. Successful code execution typically yields full control of the database host.

Attack surface

Reached over the network through the SQL Server TDS interface by invoking the sp_replwritetovarbin extended stored procedure; the CVSS vector (AV:N/AC:L/Au:S) indicates low complexity but requires a valid authenticated session. No user interaction is needed beyond issuing the procedure call.

Exploitation

Public exploit code is referenced (Exploit-DB 7501 and an Exploit-tagged advisory), and EPSS is very high at 0.87 (99.7th percentile), though the CVE is not listed in CISA KEV. No ransomware group usage is documented.

What to do

  • Apply Microsoft security bulletin MS09-004, which addresses this vulnerability, and retire or isolate unsupported SQL Server 2000/MSDE installations.
  • Restrict EXECUTE permission on sp_replwritetovarbin and other extended stored procedures to only the accounts that genuinely require it.
  • Enforce least privilege on SQL logins and avoid shared or application-wide accounts with broad database rights.
  • Block direct SQL Server access from untrusted networks and require access through controlled, monitored paths.

Detection

  • Alert on execution of sp_replwritetovarbin, especially with unusual or malformed parameter sets, via SQL Server audit or extended events.
  • Monitor SQL Server error logs and Windows event logs for access violation exceptions or unexpected service crashes.
  • Hunt for suspicious child processes spawned by sqlservr.exe, which would indicate post-exploitation code execution.
  • Baseline normal use of replication-related extended stored procedures and flag deviations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0304.html
http://osvdb.org/50917
http://secunia.com/advisories/33034 Vendor Advisory
http://securityreason.com/securityalert/4706
http://securitytracker.com/id?1021363
http://securitytracker.com/id?1021490
http://support.avaya.com/elmodocs2/security/ASA-2009-055.htm
http://www.kb.cert.org/vuls/id/696644 US Government Resource
http://www.microsoft.com/technet/security/advisory/961040.mspx
http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovarbin_memwrite.txt Exploit
http://www.securityfocus.com/archive/1/499042/100/0/threaded
http://www.securityfocus.com/archive/1/499085/100/0/threaded
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://www.securityfocus.com/bid/32710 Exploit
http://www.us-cert.gov/cas/techalerts/TA09-041A.html US Government Resource
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
http://www.vupen.com/english/advisories/2008/3380
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-004
https://exchange.xforce.ibmcloud.com/vulnerabilities/47182
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6217
https://www.exploit-db.com/exploits/7501
http://archives.neohapsis.com/archives/fulldisclosure/2008-12/0304.html
http://osvdb.org/50917
http://secunia.com/advisories/33034 Vendor Advisory
http://securityreason.com/securityalert/4706
http://securitytracker.com/id?1021363
http://securitytracker.com/id?1021490
http://support.avaya.com/elmodocs2/security/ASA-2009-055.htm
http://www.kb.cert.org/vuls/id/696644 US Government Resource
http://www.microsoft.com/technet/security/advisory/961040.mspx
http://www.sec-consult.com/files/20081209_mssql-2000-sp_replwritetovarbin_memwrite.txt Exploit
http://www.securityfocus.com/archive/1/499042/100/0/threaded
http://www.securityfocus.com/archive/1/499085/100/0/threaded
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://www.securityfocus.com/bid/32710 Exploit
http://www.us-cert.gov/cas/techalerts/TA09-041A.html US Government Resource
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
http://www.vupen.com/english/advisories/2008/3380

Track CVE-2008-5416 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0618Microsoft SQL Server Reporting Services ViewState deserialization RCESQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can…KEVEPSS 99%analysed8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed9.8CVE-2018-8273Microsoft sql server out-of-bounds write vulnerabilityA buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…EPSS 29%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%9.3CVE-2009-2501Microsoft windows 2003 server memory buffer overflow vulnerabilityHeap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Offic…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2008-5416), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.