CVE-2002-0721
Last modified
CVE-2002-0721 is a vulnerability of currently unknown severity. Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.. EPSS estimates a 46.31% chance of exploitation in the next 30 days.
Description
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Data Engine | 1.0 |
| Microsoft | Data Engine | 2000 |
| Microsoft | Sql Server | 7.0 |
| Microsoft | Sql Server | 2000 |
References
- http://www.kb.cert.org/vuls/id/399531US Government Resource
- http://www.kb.cert.org/vuls/id/818939US Government Resource
- http://www.kb.cert.org/vuls/id/939675US Government Resource
- http://www.kb.cert.org/vuls/id/399531US Government Resource
- http://www.kb.cert.org/vuls/id/818939US Government Resource
- http://www.kb.cert.org/vuls/id/939675US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0721?
How severe is CVE-2002-0721?
How do I fix CVE-2002-0721?
Are you affected by CVE-2002-0721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
