CVE-2002-0643
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
La instalación de Microsoft Data Engine 1.0 (MSDE 1.0), y Microsoft SQL Server 2000 crea ficheros setup.iss con permisos inseguros que no son eliminados después de la instalación, lo cual posibilita a usuarios locales la obtención de datos confidenciales, incluyendo contraseñas débilmente encriptadas, para obtener privilegios.
Esta vulnerabilidad también es conocida como SQL Server Installation Process May Leave Passwords on System.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2002-06-28 CVE Reserved
- 2002-07-12 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=bugtraq&m=102640092826731&w=2 | Mailing List | |
http://marc.info/?l=vuln-dev&m=102640394131103&w=2 | Mailing List | |
http://www.kb.cert.org/vuls/id/338195 | Third Party Advisory | |
http://www.securityfocus.com/bid/5203 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-035 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Data Engine Search vendor "Microsoft" for product "Data Engine" | 1.0 Search vendor "Microsoft" for product "Data Engine" and version "1.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | sp2 |
Affected
|