CVE-2002-0643
Last modified
CVE-2002-0643 is a vulnerability of currently unknown severity. The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System.". EPSS estimates a 1.70% chance of exploitation in the next 30 days.
Description
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Data Engine | 1.0 |
| Microsoft | Sql Server | 7.0 |
| Microsoft | Sql Server | 2000 |
References
- http://www.kb.cert.org/vuls/id/338195US Government Resource
- http://www.kb.cert.org/vuls/id/338195US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0643?
How severe is CVE-2002-0643?
How do I fix CVE-2002-0643?
Are you affected by CVE-2002-0643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
