// For flags

CVE-2014-4061

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka "Microsoft SQL Server Stack Overrun Vulnerability."

Microsoft SQL Server 2008 SP3, 2008 R2 SP2, y 2012 SP1 no controla debidamente el uso de la memoria en pila para el procesamiento de comandos de lotes T-SQL, lo que permite a usuarios remotos autenticados causar una denegación de servicio (cuelgue de demonio) a través de una declaración T-SQL manipulada, también conocido como 'vulnerabilidad de saturación de pila de Microsoft SQL Server.'

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-06-12 CVE Reserved
  • 2014-08-12 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2008
Search vendor "Microsoft" for product "Sql Server" and version "2008"
r2_sp2, itanium
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2008
Search vendor "Microsoft" for product "Sql Server" and version "2008"
r2_sp2, x64
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2008
Search vendor "Microsoft" for product "Sql Server" and version "2008"
r2_sp2, x86
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2008
Search vendor "Microsoft" for product "Sql Server" and version "2008"
sp3, itanium
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2008
Search vendor "Microsoft" for product "Sql Server" and version "2008"
sp3, x64
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2008
Search vendor "Microsoft" for product "Sql Server" and version "2008"
sp3, x86
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2012
Search vendor "Microsoft" for product "Sql Server" and version "2012"
sp1, x64
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2012
Search vendor "Microsoft" for product "Sql Server" and version "2012"
sp1, x86
Affected