Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability

BID:4797

Info

Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability

Bugtraq ID: 4797
Class: Configuration Error
CVE: CVE-2000-1209
Remote: Yes
Local: No
Published: May 22 2002 12:00AM
Updated: Jul 11 2009 12:46PM
Credit: Credited to Adrian Romo of Quilogy.
Vulnerable: Optima Opty-Way Enterprise 1.0
Microsoft SQL Server 2000 Desktop Engine
+ Akiva WebBoard 6.1
+ Microsoft Access 2000
+ Microsoft Application Center 2000
+ Microsoft BizTalk Server 2000 Developer Edition
+ Microsoft BizTalk Server 2000 Enterprise Edition
+ Microsoft BizTalk Server 2000 Standard Edition
+ Microsoft BizTalk Server 2002 Developer Edition
+ Microsoft BizTalk Server 2002 Enterprise Edition
+ Microsoft Office 2000
+ Microsoft Project Central Server
+ Microsoft SharePoint Team Services from Microsoft
+ Microsoft Visio 2000 Enterprise Edition
+ Microsoft Visio Enterprise Network Tools
+ Microsoft Visual FoxPro 6.0
+ Microsoft Visual Studio 6.0
+ Microsoft Visual Studio .NET Academic Edition 0
+ Microsoft Visual Studio .NET Enterprise Architect Edition
+ Microsoft Visual Studio .NET Enterprise Developer Edition
+ Microsoft Visual Studio .NET Professional Edition
+ SmartMax Software MailMax 5.0
+ Veritas Software Backup Exec for Windows Servers 9.0
Microsoft MSDE 1.0
+ Microsoft Visio 2000 Enterprise Edition SR1
+ Microsoft Visio 2000 Enterprise Edition SR1
+ Microsoft Visio 2000 Enterprise Edition
+ Microsoft Visio 2000 Enterprise Edition
+ Microsoft Visual Studio 6.0
+ Microsoft Visual Studio 6.0
+ Optima Opty-Way Enterprise 1.0
+ Optima Opty-Way Enterprise 1.0
+ Websense Reporter 6.3.1
+ Websense Reporter 6.3.1
Compaq Open SAN Manager 1.0 c
Compaq Insight Manager XE 2.2
Compaq Insight Manager XE 2.1 c
Compaq Insight Manager XE 2.1 b
Compaq Insight Manager XE 2.1
Compaq Insight Manager XE 1.21
Compaq Insight Manager XE 1.1
Compaq Insight Manager 7.0 SP1
Compaq Insight Manager 7.0
Avaya CentreVu Explorer II
Avaya CentreVu / Nice Call Recording System 8.5
Not Vulnerable:

Discussion

Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability

It has been reported Microsoft MSDE and SQL Server 2000 Desktop Engine are configured by default with a null administrative password by default. Remote attackers may exploit this flaw to gain administrative access to the database if the password has not been manually changed.

Compaq Insight Manager XE versions 1.1 and later include the capability to use MSDE. MSDE is not installed as part of Compaq Insight Manager by default. When MSDE is installed via Compaq Insight Manager, it is recommended during that install that users change the 'sa' administrative password. Installs via Compaq Management CD or Insight Manager 7 softpaqs include no such recommendation.

It should be noted that a worm is currently propagating due to default null passwords in Microsoft SQL server and derived products such as MSDE and SQL Server 2000 Desktop Engine.

Exploit / POC

Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability

No exploit code is required.

Solution / Fix

Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability

Solution:
Avaya have released a security advisory that contains recommended actions to fix this issue in CentreVu Explorer II and CentreVu/Nice Call Recording System 8.5 and later. Please see the referenced advisory for further details.

Microsoft has released security recommendations for administrators of SQL server and related products. A link to this document is included in the links section of this record bulletin.

Some Compaq Insight Manager releases include the capability to use MSDE. If MSDE is installed, users are advised to ensure that the default null administrative password is changed. The service must be restarted for any changes to take effect.

HP has released a security advisory (HPSBMA01168) detailing a revision to the Compaq advisory SSRT2195. Please see the referenced advisory for further information.

Setting a hard-to-guess password will effectively eliminate this vulnerability.

A patch is available for Compaq Open SAN Manager:


Compaq Open SAN Manager 1.0 c

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report