Description
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
References (6)
Core 6
Core References
US Government Resource third-party-advisory
x_refsource_cert
http://www.cert.org/advisories/CA-2002-22.html
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/796313
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/9523.php
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5205
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1025
Scores
EPSS
0.4970
EPSS Percentile
98.8%
Details
Status
published
Products (2)
microsoft/msde
2000
microsoft/sql_server
2000
Published
Jul 23, 2002
Tracked Since
Feb 18, 2026