20030709 Pipe Filename Local Privilege Escalation FAQmailing list
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html CVE-2003-0496
Microsoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (1)
Record summary
CVE-2003-0496 has a selected CVSS score of 7.2; EIP currently links 2 catalogued exploits.
Description
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMicrosoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (1)ExploitDB exploitby MaceoNot analyzed1 file
ExploitDBMicrosoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (2)ExploitDB exploitby MaceoNot analyzed1 file
References
520030714 @stake named pipe exploitmailing list
http://marc.info/?l=bugtraq&m=105820282607865&w=2 20030715 CreateFile exploit, (working)mailing list
http://marc.info/?l=bugtraq&m=105830986720243&w=2 A070803-1Vendor advisory
http://www.atstake.com/research/advisories/2003/a070803-1.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0496