{"api_version":"1","generated_at":"2026-07-23T10:35:41+00:00","cve":"CVE-1999-1556","urls":{"html":"https://cve.report/CVE-1999-1556","api":"https://cve.report/api/cve/CVE-1999-1556.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-1999-1556","nvd":"https://nvd.nist.gov/vuln/detail/CVE-1999-1556"},"summary":{"title":"CVE-1999-1556","description":"Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.","state":"PUBLISHED","assigner":"mitre","published_at":"1998-06-29 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://marc.info/?l=ntbugtraq&m=90222453431645&w=2","name":"http://marc.info/?l=ntbugtraq&m=90222453431645&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'MS SQL Server 6.5 stores password in unprotected area of registry' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/109","name":"http://www.securityfocus.com/bid/109","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"NT SQL Server Password Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7354","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7354","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-1999-1556","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-1999-1556","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"1999","cve_id":"1556","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"sql_server","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-01T17:18:07.561Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19980629 MS SQL Server 6.5 stores password in unprotected registry keys","tags":["mailing-list","x_refsource_NTBUGTRAQ","x_transferred"],"url":"http://marc.info/?l=ntbugtraq&m=90222453431645&w=2"},{"name":"109","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/109"},{"name":"mssql-sqlexecutivecmdexec-password(7354)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7354"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"1998-06-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2004-07-23T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19980629 MS SQL Server 6.5 stores password in unprotected registry keys","tags":["mailing-list","x_refsource_NTBUGTRAQ"],"url":"http://marc.info/?l=ntbugtraq&m=90222453431645&w=2"},{"name":"109","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/109"},{"name":"mssql-sqlexecutivecmdexec-password(7354)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7354"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-1999-1556","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19980629 MS SQL Server 6.5 stores password in unprotected registry keys","refsource":"NTBUGTRAQ","url":"http://marc.info/?l=ntbugtraq&m=90222453431645&w=2"},{"name":"109","refsource":"BID","url":"http://www.securityfocus.com/bid/109"},{"name":"mssql-sqlexecutivecmdexec-password(7354)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7354"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-1999-1556","datePublished":"2004-09-01T04:00:00.000Z","dateReserved":"2001-08-31T00:00:00.000Z","dateUpdated":"2024-08-01T17:18:07.561Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"1998-06-29 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:sql_server:6.5:*:*:*:*:*:*:*","matchCriteriaId":"08CB788D-CFEC-4F8B-9158-8A15319FAB49"}]}]}]},"legacy_mitre":{"record":{"CveYear":"1999","CveId":"1556","Ordinal":"1","Title":"CVE-1999-1556","CVE":"CVE-1999-1556","Year":"1999"},"notes":[{"CveYear":"1999","CveId":"1556","Ordinal":"1","NoteData":"Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.","Type":"Description","Title":"CVE-1999-1556"},{"CveYear":"1999","CveId":"1556","Ordinal":"2","NoteData":"2004-09-01","Type":"Other","Title":"Published"},{"CveYear":"1999","CveId":"1556","Ordinal":"3","NoteData":"2004-07-22","Type":"Other","Title":"Modified"}]}}}