Microsoft SQL Server / MSDE Named Pipes Privilege Escalation Vulnerability
BID:8276
Info
Microsoft SQL Server / MSDE Named Pipes Privilege Escalation Vulnerability
| Bugtraq ID: | 8276 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0230 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | This vulnerability was announced by the vendor in a security advisory. |
| Vulnerable: |
Microsoft SQL Server 2000 Desktop Engine Microsoft SQL Server 2000 SP3a Microsoft SQL Server 2000 SP3 Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP4 Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 Microsoft Data Engine (MSDE) 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft SQL Server / MSDE Named Pipes Privilege Escalation Vulnerability
Microsoft SQL Server and the Microsoft Data Engine have been reported prone to a privilege escalation vulnerability via named pipes.
It has been reported that a named pipe used to control certain connection attempts to the SQL server is prone to a vulnerability that may provide for the escalation of privileges.
If successful, a local attacker may seize control of the named pipe and thereby inherit the permissions of a user who is attempting to connect to the SQL server.
Microsoft SQL Server and the Microsoft Data Engine have been reported prone to a privilege escalation vulnerability via named pipes.
It has been reported that a named pipe used to control certain connection attempts to the SQL server is prone to a vulnerability that may provide for the escalation of privileges.
If successful, a local attacker may seize control of the named pipe and thereby inherit the permissions of a user who is attempting to connect to the SQL server.
References
Microsoft SQL Server / MSDE Named Pipes Privilege Escalation Vulnerability
References:
References:
- Microsoft Security Bulletin MS03-031 (Microsoft)
- SQL Server/MSDE-Based Applications (sqlsecurity.com)