Microsoft Issues Advisory on SQL Vulnerability
...Consult on Dec. 9 . The disclosure says that Microsoft had been notified of it in April, had acknowledged it, but had stopped responding to SEC Consult requests for status. The vulnerability is in a stored procedure named sp replwritetovarbin. It is possible to cause this stored procedure to invoke a heap buffer overflow in the server and...
