CVE-2002-0721
Microsoft SQL 2000/7.0 - Agent Jobs Privilege Escalation
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
Microsoft SQL Server 7.0 y 2000 se instala con permisos débiles para ciertos procedimientos almacenados (stored procedures) extendidos que están asociados con funciones de ayuda, lo que podría permitir a usuairos sin privilegios, y posiblemente atacantes remotos, ejecutar procedimentos almacenados con privilegios de administrador.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2002-07-22 CVE Reserved
- 2002-08-15 First Exploit
- 2002-08-20 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/ntbugtraq/2002-q3/0087.html | Mailing List | |
http://marc.info/?l=bugtraq&m=102950473002959&w=2 | Mailing List | |
http://marc.info/?l=ntbugtraq&m=102950792606475&w=2 | Mailing List | |
http://www.kb.cert.org/vuls/id/399531 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/818939 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/939675 | Third Party Advisory | |
http://www.ngssoftware.com/advisories/mssql-esppu.txt | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/21718 | 2002-08-15 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-043 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Data Engine Search vendor "Microsoft" for product "Data Engine" | 1.0 Search vendor "Microsoft" for product "Data Engine" and version "1.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Data Engine Search vendor "Microsoft" for product "Data Engine" | 2000 Search vendor "Microsoft" for product "Data Engine" and version "2000" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 7.0 Search vendor "Microsoft" for product "Sql Server" and version "7.0" | sp4 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sql Server Search vendor "Microsoft" for product "Sql Server" | 2000 Search vendor "Microsoft" for product "Sql Server" and version "2000" | sp2 |
Affected
|