Lucene search

K
cve[email protected]CVE-2002-0642
HistoryApr 02, 2003 - 5:00 a.m.

CVE-2002-0642

2003-04-0205:00:00
web.nvd.nist.gov
53
microsoft
sql server
registry key
insecure permissions
local users
privilege escalation
cve-2002-0642
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.974 High

EPSS

Percentile

99.9%

The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka “Incorrect Permission on SQL Server Service Account Registry Key.”

Affected configurations

NVD
Node
microsoftmsdeMatch2000
OR
microsoftsql_serverMatch2000

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.974 High

EPSS

Percentile

99.9%