CVE-1999-1556
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/sql server
- Source
- cve@mitre.org
References
- http://marc.info/?l=ntbugtraq&m=90222453431645&w=2
- http://www.securityfocus.com/bid/109Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7354
- http://marc.info/?l=ntbugtraq&m=90222453431645&w=2
- http://www.securityfocus.com/bid/109Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7354
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.