// For flags

CVE-2002-0721

Microsoft SQL 2000/7.0 - Agent Jobs Privilege Escalation

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

Microsoft SQL Server 7.0 y 2000 se instala con permisos débiles para ciertos procedimientos almacenados (stored procedures) extendidos que están asociados con funciones de ayuda, lo que podría permitir a usuairos sin privilegios, y posiblemente atacantes remotos, ejecutar procedimentos almacenados con privilegios de administrador.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2002-07-22 CVE Reserved
  • 2002-08-15 First Exploit
  • 2002-08-20 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Data Engine
Search vendor "Microsoft" for product "Data Engine"
1.0
Search vendor "Microsoft" for product "Data Engine" and version "1.0"
-
Affected
Microsoft
Search vendor "Microsoft"
Data Engine
Search vendor "Microsoft" for product "Data Engine"
2000
Search vendor "Microsoft" for product "Data Engine" and version "2000"
-
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
7.0
Search vendor "Microsoft" for product "Sql Server" and version "7.0"
-
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
7.0
Search vendor "Microsoft" for product "Sql Server" and version "7.0"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
7.0
Search vendor "Microsoft" for product "Sql Server" and version "7.0"
sp2
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
7.0
Search vendor "Microsoft" for product "Sql Server" and version "7.0"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
7.0
Search vendor "Microsoft" for product "Sql Server" and version "7.0"
sp4
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
-
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2000
Search vendor "Microsoft" for product "Sql Server" and version "2000"
sp2
Affected