A heap-based buffer overflow exists in Microsoft SQL Server 2000 (various SP4 builds), SQL Server 2005 SP2, MSDE 2000 SP4, WMSDE on Windows Server 2003, and Windows Internal Database (WYukon) SP2. The vulnerability is triggered when the sp_replwritetovarbin extended stored procedure is called with invalid parameters, leading to a memory overwrite condition. This can be exploited by remote authenticated users to cause an access violation (DoS) or potentially execute arbitrary code within the SQL Server process context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'ms09_004_sp_replwritetovarbin.rb', which exploits a heap-based buffer overflow vulnerability (CVE-2008-5416, MS09-004) in the undocumented 'sp_replwritetovarbin' extended stored procedure of Microsoft SQL Server 2000 and 2005, as well as Windows Internal Database and MSDE. The exploit requires authentication to the SQL Server (or an SQL injection vector) and leverages advanced memory corruption techniques, including return-oriented programming, to achieve reliable code execution. The module is highly weaponized, supporting customizable payloads and automatic or manual targeting of specific SQL Server versions. The main attack vector is network-based, targeting the SQL Server service (typically on TCP port 1433). The exploit is part of the Metasploit framework and is structured as a standard Ruby module, inheriting from Msf::Exploit::Remote::MSSQL. The code includes logic for encoding payloads to avoid bad characters and for handling different target versions. The repository is focused, containing only the exploit module file.
This repository contains a single Metasploit module that exploits a heap-based buffer overflow vulnerability (CVE-2008-5416, MS09-004) in the undocumented 'sp_replwritetovarbin' extended stored procedure of Microsoft SQL Server 2000 and 2005, as well as Windows Internal Database and MSDE. The exploit leverages SQL injection to trigger the overflow, allowing for reliable code execution within the context of the SQL Server process. The module is written in Ruby and is part of the Metasploit Framework, utilizing the Msf::Exploit::Remote::MSSQL_SQLI mixin for SQL Server interaction. The payload is customizable and typically results in a reverse shell or Meterpreter session. The exploit requires network access to the SQL Server and valid credentials or a SQL injection vector. The only fingerprintable endpoint is the 'sp_replwritetovarbin' stored procedure. The code is mature and operational, providing a reliable method for remote code execution on unpatched systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.