PT-2002-1678 · Microsoft · Sql Server Desktop Engine (Msde) 2000+1
Published
2002-07-23
·
Updated
2018-10-12
·
CVE-2002-0642
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server 2000 (affected versions not specified)
Microsoft SQL Server Desktop Engine (MSDE) 2000 (affected versions not specified)
Description
The issue concerns insecure permissions on a registry key in Microsoft SQL Server 2000, including MSDE 2000, which contains SQL Server service account information. This allows local users to gain privileges.
Recommendations
For Microsoft SQL Server 2000, update the permissions on the registry key containing the SQL Server service account information to prevent local users from gaining privileges.
For Microsoft SQL Server Desktop Engine (MSDE) 2000, update the permissions on the registry key containing the SQL Server service account information to prevent local users from gaining privileges.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sql Server 2000
Sql Server Desktop Engine (Msde) 2000