CVE-2002-1138
Summary
| CVE | CVE-2002-1138 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-10-11 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs." |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Data Engine | 1.0 | All | All | All |
| Application | Microsoft | Data Engine | 2000 | All | All | All |
| Application | Microsoft | Sql Server | 2000 | All | All | All |
| Application | Microsoft | Sql Server | 2000 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2000 | sp2 | All | All |
| Application | Microsoft | Sql Server | 7.0 | All | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp1 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp2 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp3 | All | All |
| Application | Microsoft | Sql Server | 7.0 | sp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ISS X-Force Database: mssql-agent-create-files (10257): Microsoft SQL Server Agent scheduled jobs could create malicious output files | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Vendor Advisory |
| www.ciac.org/ciac/bulletins/n-003.shtml | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| Microsoft Security Bulletin MS02-056 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.