CVE-2002-0642
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 49.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 49.70% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/msde · microsoft/sql server
- Source
- cve@mitre.org
References
- http://www.cert.org/advisories/CA-2002-22.htmlUS Government Resource
- http://www.iss.net/security_center/static/9523.php
- http://www.kb.cert.org/vuls/id/796313US Government Resource
- http://www.securityfocus.com/bid/5205
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1025
- http://www.cert.org/advisories/CA-2002-22.htmlUS Government Resource
- http://www.iss.net/security_center/static/9523.php
- http://www.kb.cert.org/vuls/id/796313US Government Resource
- http://www.securityfocus.com/bid/5205
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1025
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.