CVE-2002-0721
Summary
| CVE | CVE-2002-0721 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-09-05 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Data Engine | 1.0 | All | All | All |
| Application | Microsoft | Data Engine | 2000 | All | All | All |
| Application | Microsoft | Sql Server | 2000 | All | All | All |
| Application | Microsoft | Sql Server | 2000 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2000 | sp2 | All | All |
| Application | Microsoft | Sql Server | 7.0 | All | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp1 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp2 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp3 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| archives.neohapsis.com/archives/ntbugtraq/2002-q3/0087.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| 'Microsoft SQL Server Extended Stored Procdure privilege upgrade vulnerabilities (#NISR15002002A)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'Microsoft SQL Server Extended Stored Procdure privilege upgrade' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Microsoft Security Bulletin MS02-043 - Moderate | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| CERT/CC Vulnerability Note VU#399531 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CERT/CC Vulnerability Note VU#939675 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| www.ngssoftware.com/advisories/mssql-esppu.txt | af854a3a-2127-422b-91ae-364da2661108 | www.ngssoftware.com | |
| CERT/CC Vulnerability Note VU#818939 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.