PT-2002-2142 · Microsoft · Desktop Engine+2

Published

2002-10-21

·

Updated

2018-10-12

·

CVE-2002-1145

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft SQL Server versions 7.0 through 2000 Microsoft Data Engine (MSDE) version 1.0 Microsoft Desktop Engine (MSDE) 2000
Description: The issue concerns the xp runwebtask stored procedure in the Web Tasks component, which can be executed by PUBLIC. This allows an attacker to gain privileges by updating a webtask owned by the database owner through the msdb.dbo.mswebtasks table, due to weak permissions.
Recommendations: For Microsoft SQL Server versions 7.0 through 2000, restrict access to the xp runwebtask stored procedure to prevent unauthorized execution. For Microsoft Data Engine (MSDE) version 1.0, limit access to the msdb.dbo.mswebtasks table to minimize the risk of exploitation. For Microsoft Desktop Engine (MSDE) 2000, consider revoking PUBLIC execute permissions on the xp runwebtask stored procedure as a temporary workaround.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1145

Affected Products

Data Engine
Desktop Engine
Sql Server