CVE-2003-0496

Microsoft SQL Server <Windows 2000 SP4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Maceo · clocalwindows
https://www.exploit-db.com/exploits/22883
exploitdb WORKING POC VERIFIED
by Maceo · clocalwindows
https://www.exploit-db.com/exploits/22882

Scores

EPSS 0.0218
EPSS Percentile 84.4%

Details

Status published
Products (2)
microsoft/windows_2000 (4 CPE variants)
microsoft/windows_2000_terminal_services (4 CPE variants)
Published Aug 18, 2003
Tracked Since Feb 18, 2026