Microsoft SQL Server 7.0 and 2000 Vulnerability in Job Output Handling
CVE-2002-1138

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
11 October 2002

Summary

Microsoft SQL Server 7.0 and 2000, along with its related Microsoft Data Engine products, exhibit a vulnerability in how output files for scheduled jobs are managed. The system writes these files using its own privileges rather than the privileges of the user who initiated the job. This oversight allows potential attackers to manipulate and overwrite system files, leading to possible unauthorized access and altered system integrity.

References

EPSS Score

11% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.