Microsoft · Sql Server Enterprise Manager · CVE-2007-4814
Name of the Vulnerable Software and Affected Versions:
Microsoft SQL Server Enterprise Manager version 8.05.2004
Description:
A buffer overflow issue exists in the SQLServer ActiveX control within the Distributed Management Objects OLE DLL (sqldmo.dll) due to improper handling of a long second argument to the `Start` method. This allows remote attackers to execute arbitrary code.
Recommendations:
For Microsoft SQL Server Enterprise Manager version 8.05.2004, consider restricting access to the vulnerable ActiveX control until a patch is available. As a temporary workaround, avoid using the `Start` method with long arguments to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.