CVE-2002-1123
Microsoft SQL Server <2000 - RCE
Title source: llmDescription
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16398
exploitdb
WORKING POC
VERIFIED
by Dave Aitel · remotewindows
https://www.exploit-db.com/exploits/21693
metasploit
WORKING POC
GOOD
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/mssql/ms02_056_hello.rb
References (6)
Scores
EPSS
0.8914
EPSS Percentile
99.5%
Details
Status
published
Products (2)
microsoft/data_engine
2000
microsoft/sql_server
2000 (3 CPE variants)
Published
Sep 24, 2002
Tracked Since
Feb 18, 2026