Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-040
http://www.securityfocus.com/bid/5372