CVE-2002-0721
Last modified
CVE-2002-0721 is a vulnerability of currently unknown severity. Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.. EPSS estimates a 46.31% chance of exploitation in the next 30 days.
Description
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Data Engine | 1.0 |
| Microsoft | Data Engine | 2000 |
| Microsoft | Sql Server | 7.0 |
| Microsoft | Sql Server | 2000 |
References
- http://www.kb.cert.org/vuls/id/399531US Government Resource
- http://www.kb.cert.org/vuls/id/818939US Government Resource
- http://www.kb.cert.org/vuls/id/939675US Government Resource
- http://www.kb.cert.org/vuls/id/399531US Government Resource
- http://www.kb.cert.org/vuls/id/818939US Government Resource
- http://www.kb.cert.org/vuls/id/939675US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0721?
How severe is CVE-2002-0721?
How do I fix CVE-2002-0721?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0715Vulnerability in Squid before 2.4.STABLE6 related to proxy a…
- CVE-2002-0716Format string vulnerability in crontab for SCO OpenServer 5.…
- CVE-2002-0717PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denia…
- CVE-2002-0718Web authoring command in Microsoft Content Management Server…
- CVE-2002-0719SQL injection vulnerability in the function that services fo…
- CVE-2002-0720A handler routine for the Network Connection Manager (NCM) i…
- CVE-2002-0722Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote…
- CVE-2002-0723Microsoft Internet Explorer 5.5 and 6.0 does not properly ve…
- CVE-2002-0724Buffer overflow in SMB (Server Message Block) protocol in Mi…
- CVE-2002-0725NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allo…5.5
- CVE-2002-0726Buffer overflow in Microsoft Terminal Services Advanced Clie…
- CVE-2002-0727The Host function in Microsoft Office Web Components (OWC) 2…
Are you affected by CVE-2002-0721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
