Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability
BID:5481
Info
Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability
| Bugtraq ID: | 5481 |
| Class: | Design Error |
| CVE: |
CVE-2002-0721 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Credit is given to David Litchfield of Next Generation Security Software Ltd., Chip Andrews of www.sqlsecurity.com and Timothy Mullen. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine 2000 Microsoft Data Engine (MSDE) 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability
Microsoft SQL Server 2000 uses various extended stored procedures to allow database designers to create their own external routines.
Some of these extended stored procedures have weak permissions, which could allow a user with low permissions to perform actions on the database in the context of the SQL Server Service Account.
Microsoft SQL Server 2000 uses various extended stored procedures to allow database designers to create their own external routines.
Some of these extended stored procedures have weak permissions, which could allow a user with low permissions to perform actions on the database in the context of the SQL Server Service Account.
Exploit / POC
Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability
Solution:
Microsoft has revised their advisory. Microsoft recommends that users of SQL 2000 and MSDE 2000 apply the patch from MS02-061 which contains additional security fixes:
Microsoft SQL Server 2000
Microsoft SQL Server 7.0 SP1
Microsoft SQL Server 7.0 SP3
Microsoft SQL Server 7.0 SP4
Microsoft SQL Server 2000 SP1
Microsoft SQL Server 7.0 SP2
Microsoft SQL Server 2000 SP2
Microsoft SQL Server 7.0
Solution:
Microsoft has revised their advisory. Microsoft recommends that users of SQL 2000 and MSDE 2000 apply the patch from MS02-061 which contains additional security fixes:
Microsoft SQL Server 2000
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0 SP1
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 7.0 SP3
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 7.0 SP4
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 2000 SP1
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0 SP2
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 2000 SP2
-
Microsoft Q316333
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&sd=tec h -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
References
Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-043 (Microsoft)
- Microsoft Security Bulletin MS02-061 (Microsoft)
- Microsoft SQL Server Homepage (Microsoft)