CVE-2002-1981

Microsoft SQL Server <2000 SP2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5604
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10012.php
Vendor Advisory mailing-list x_refsource_bugtraq
http://seclists.org/lists/bugtraq/2002/Sep/0009.html

Scores

EPSS 0.0458
EPSS Percentile 90.7%

Details

Status published
Products (1)
microsoft/sql_server 2000 (3 CPE variants)
Published Dec 31, 2002
Tracked Since Feb 18, 2026