PT-2003-1959 · Microsoft+1 · Netapi32.Dll+1

Publicado

2003-11-21

·

Atualizado

2017-07-11

·

CVE-2003-0938

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP DB versions 7.4.03.27 and earlier
Description The issue allows local users to gain SYSTEM privileges by exploiting a malicious "NETAPI32.DLL" in the current working directory. This DLL is loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.
Recommendations For SAP DB versions 7.4.03.27 and earlier, consider restricting access to the SQLAT stored procedure until a fix is available. As a temporary workaround, ensure that no malicious "NETAPI32.DLL" is present in the current working directory to prevent unauthorized privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0938

Produtos afetados

Netapi32.Dll
Sap Db