Slammer, also known as the SQL Slammer worm, was a fast-spreading network worm that targeted Microsoft SQL Server systems by exploiting the SQL Server Resolution Service heap overflow vulnerability CVE-2002-0649 over UDP 1434. It became one of the defining early-2000s Internet worm outbreaks and is widely cited alongside Code Red, Blaster, Sasser, and Conficker as an example of how rapidly self-propagating malware can cause large-scale disruption when patching lags behind exposure.
Slammer propagated by scanning for vulnerable hosts and transmitting its exploit directly over the network, requiring no user interaction once reachable targets were exposed. Its primary impact was denial of service through explosive propagation and network congestion rather than data theft or stealthy persistence. The worm disrupted enterprise and operational environments, including a well-documented incident at the Davis-Besse nuclear power plant in January 2003, where infection of a private network disabled a safety monitoring system for nearly five hours and caused a plant process computer outage for about six hours after entering through an unsecured contractor connection and bypassing perimeter protections.
Slammer is frequently referenced in discussions of critical infrastructure risk because it demonstrated how indiscriminate worm activity against common enterprise software could spill into industrial and safety-related environments. It is also historically associated with attacks against the SQL Server Resolution Service on UDP 1434, which led defenders and platform vendors to recommend blocking or restricting that service where possible and prioritizing rapid patch deployment. Slammer’s outbreak reinforced enduring defensive lessons around vulnerability management, network segmentation, limiting unnecessary exposure of database services, and controlling third-party connectivity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
References include http://www.microsoft.com/technet/security/virus/alerts/slammer.asp in relation to the Microsoft SQL Server 2000 UDP 1434 heap overflow vulnerability (CVE-2002-0649).
6 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical worm outbreak used for comparison with the proposed Intelligent Worm model.
A highly disruptive worm included among the major early internet worm outbreaks.
Referenced as a historically devastating malware incident associated with exploitation of software vulnerabilities.
A worm mentioned as historical background to illustrate why default SQL Server ports and services are attractive attack targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.