PT-2002-1677 · Microsoft · Sql Server Desktop Engine (Msde) 2000+1

Published

2002-07-12

·

Updated

2018-10-12

·

CVE-2002-0641

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server 2000 Microsoft SQL Server Desktop Engine (MSDE) 2000
Description A buffer overflow issue exists in the bulk insert procedure, allowing attackers with database administration privileges to execute arbitrary code. This can be achieved by using a long filename in the BULK INSERT query.
Recommendations For Microsoft SQL Server 2000, consider restricting database administration privileges to minimize the risk of exploitation. For Microsoft SQL Server Desktop Engine (MSDE) 2000, avoid using long filenames in the BULK INSERT query until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0641

Affected Products

Sql Server 2000
Sql Server Desktop Engine (Msde) 2000