PT-2001-1567 · Microsoft · Sql Server
Publicado
2001-07-21
·
Atualizado
2018-10-12
·
CVE-2001-0344
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server versions 7.0 and 2000 Gold
Description
A security issue in Microsoft SQL Server allows local database users to elevate their privileges. This is achieved by reusing a cached connection of the sa administrator account through an SQL query method in Mixed Mode.
Recommendations
For Microsoft SQL Server version 7.0, consider restricting access to the sa administrator account to prevent privilege escalation.
For Microsoft SQL Server 2000 Gold, restrict the use of Mixed Mode to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sql Server