SQL Slammer was the 2003 internet worm that exploited a buffer overflow in Microsoft SQL Server 2000. It began spreading on January 25, 2003, and rapidly infected vulnerable servers.
The worm used a flaw in the Microsoft SQL Server 2000 Resolution Service. Its tiny code sample generated traffic that spread from one vulnerable system to another, producing a dramatic increase in network congestion around the world.
SQL Slammer did not primarily operate like an email virus requiring users to open an attachment. It scanned for vulnerable hosts directly, which helped it spread extremely quickly. Reports measured its growth in seconds and minutes rather than hours or days.
The worm is sometimes confused with Code Red, which targeted Microsoft IIS web servers in 2001. SQL Slammer instead focused on a database-server vulnerability and became a landmark example of automated network propagation.