Microsoft SQL Server Web Task Stored Procedure Privilege Escalation Vulnerability
BID:5980
Info
Microsoft SQL Server Web Task Stored Procedure Privilege Escalation Vulnerability
| Bugtraq ID: | 5980 |
| Class: | Configuration Error |
| CVE: |
CVE-2002-1145 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Martin Rakhmanoff <[email protected]> and David Litchfield of Next Generation Security Software Ltd. are given credit. |
| Vulnerable: |
Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine 2000 Microsoft Data Engine (MSDE) 1.0 Cisco Unity Server 4.0 Cisco Unity Server 3.3 Cisco Unity Server 3.2 Cisco Unity Server 3.1 Cisco Unity Server 3.0 Cisco Intelligent Contact Manager 5.0 Cisco E-Mail Manager Cisco Call Manager 3.3 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 |
| Not Vulnerable: |
Cisco Building Broadband Service Manager (BBSM) 5.2 |
Discussion
Microsoft SQL Server Web Task Stored Procedure Privilege Escalation Vulnerability
Microsoft has reported a vulnerability in SQL Server. According to the report, the vulnerability may be exploited by malicious database users to elevate privileges.
Web tasks create HTML files containing queried data. They are invoked with a stored procedure. By default, the privileges required to execute the stored procedure are minimal. This poses a threat as unprivileged SQL users may run the procedure and invoke Web Tasks. This may result in elevated privileges.
In addition, the table that stores Web Tasks itself has weak permission settings. Malicious users may also be able to modify, delete or create Web Tasks further compounding the threat.
Microsoft has reported a vulnerability in SQL Server. According to the report, the vulnerability may be exploited by malicious database users to elevate privileges.
Web tasks create HTML files containing queried data. They are invoked with a stored procedure. By default, the privileges required to execute the stored procedure are minimal. This poses a threat as unprivileged SQL users may run the procedure and invoke Web Tasks. This may result in elevated privileges.
In addition, the table that stores Web Tasks itself has weak permission settings. Malicious users may also be able to modify, delete or create Web Tasks further compounding the threat.
Solution / Fix
Microsoft SQL Server Web Task Stored Procedure Privilege Escalation Vulnerability
Solution:
Microsoft has released an updated cumulative patch for this and other security issues, which includes an installer.
Cisco has released an advisory. Information about obtaining and applying fixes is available in the referenced advisory.
Fixes available:
Microsoft SQL Server 2000
Microsoft SQL Server 7.0 SP4
Cisco E-Mail Manager
Microsoft SQL Server 2000 SP1
Microsoft SQL Server 2000 SP2
Cisco Call Manager 3.3
Cisco Intelligent Contact Manager 5.0
Solution:
Microsoft has released an updated cumulative patch for this and other security issues, which includes an installer.
Cisco has released an advisory. Information about obtaining and applying fixes is available in the referenced advisory.
Fixes available:
Microsoft SQL Server 2000
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 7.0 SP4
-
Microsoft Q327068
Patch released in MS02-061.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q327068&sd=tec h
Cisco E-Mail Manager
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 SP1
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Microsoft SQL Server 2000 SP2
-
Microsoft Q316333
Patch released in MS02-061.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&sd=tec h -
Microsoft Q316333
Updated cumulative patch.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q316333&sd=tec h -
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
Cisco Call Manager 3.3
-
Cisco SQL2K-MS02-061.exe
http://www.cisco.com/tacpage/sw-center/telephony/crypto/voice-apps/
Cisco Intelligent Contact Manager 5.0
-
Microsoft sql2ksp3
http://www.microsoft.com/sql/downloads/2000/sp3.asp?SD=GN&LN=en-us&gss nb=1
References
Microsoft SQL Server Web Task Stored Procedure Privilege Escalation Vulnerability
References:
References: