CVE-2002-0643
Summary
| CVE | CVE-2002-0643 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-07-23 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System." |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Data Engine | 1.0 | All | All | All |
| Application | Microsoft | Sql Server | 2000 | All | All | All |
| Application | Microsoft | Sql Server | 2000 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2000 | sp2 | All | All |
| Application | Microsoft | Sql Server | 7.0 | All | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp1 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp2 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'SQL Server 7 & 2000 Installation process and Service Packs write encoded passwords to a file' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'SQL Server 7 & 2000 Installation process and Service Packs write encoded passwords to a file' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Microsoft Security Bulletin MS02-035 - Moderate | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| CERT/CC Vulnerability Note VU#338195 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Microsoft MS-SQL Server Installation Password Caching Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.