PT-2003-1398 · Microsoft+1 · Msde+1

Publicado

2003-08-01

·

Atualizado

2008-09-10

·

CVE-2003-0148

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MSDE via McAfee ePolicy Orchestrator versions 2.0 through 3.0
Description: The issue allows attackers to execute arbitrary code by obtaining the database administrator username and encrypted password from the ePO server, cracking the password due to weak cryptography, and then using the password to pass commands through xp cmdshell().
Recommendations: For MSDE via McAfee ePolicy Orchestrator versions 2.0 through 3.0, consider restricting access to the xp cmdshell() function to minimize the risk of exploitation. Additionally, strengthen the password encryption to prevent cracking due to weak cryptography.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0148

Produtos afetados

Msde
Epolicy Orchestrator