A local user or remote authenticated user could cause the database service to crash or could execute arbitrary code with the privileges of the database service. A local user or remote authenticated user could execute arbitrary operating system commands with the privileges of the SQL Server Agent Proxy account.

This patch eliminates two newly discovered vulnerabilities affecting SQL Server 2000 and MSDE 2000

For more information and patch availability