CVE-2002-0642
high · 7.2The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
7.2
CVSS
49.7%
EPSS (exploit prob.)
99th
EPSS percentile
2002-07-23
Published
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | msde | 2000 |
| microsoft | sql_server | 2000 |
Check a specific version with /api/v1/cve/match.
References
- http://www.cert.org/advisories/CA-2002-22.html
- http://www.iss.net/security_center/static/9523.php
- http://www.kb.cert.org/vuls/id/796313
- http://www.securityfocus.com/bid/5205
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1025
- http://www.cert.org/advisories/CA-2002-22.html
- http://www.iss.net/security_center/static/9523.php
- http://www.kb.cert.org/vuls/id/796313
- http://www.securityfocus.com/bid/5205
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1025
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0642