Vulnerability CVE-2002-1138


Published: 2002-10-11   Modified: 2012-02-12

Description:
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Microsoft -> Data engine 
Microsoft -> Sql server 

 References:
http://www.ciac.org/ciac/bulletins/n-003.shtml
http://www.iss.net/security_center/static/10257.php
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-056

Copyright 2021, cxsecurity.com

 

Back to Top