Description
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=90222453431645&w=2
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/109
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7354
Scores
EPSS
0.0118
EPSS Percentile
64.7%
Details
Status
published
Products (1)
microsoft/sql_server
6.5
Published
Jun 29, 1998
Tracked Since
Feb 18, 2026