Microsoft SQL Worm/Spida
Basically it a fairly simple little brute force worm that will give the attacker access to the database...But, of course you can pretty much avoid being attacked if your SQL server is inside the firewall (I hope none of you out there have your server outside... I can't find a reason why anyone would)..
Security Focus
Microsoft Bulliten
SANS Analysis
Slashdot Article [ Above links pulled from there ]