Vulnerability Name: | CVE-2003-0496 (CCN-12530) | ||||||||
Assigned: | 2003-07-08 | ||||||||
Published: | 2003-07-08 | ||||||||
Updated: | 2019-04-30 | ||||||||
Summary: | Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Jul 09 2003 - 10:39:50 CDT Pipe Filename Local Privilege Escalation FAQ Source: CCN Type: BugTraq Mailing List, Tue Jul 15 2003 - 16:10:35 CDT CreateFile exploit, (working) Source: CCN Type: VulnWatch Mailing List, Tue Jul 08 2003 - 09:46:39 CDT Named Pipe Filename Local Privilege Escalation Source: VULNWATCH Type: Patch, Vendor Advisory 20030709 Pipe Filename Local Privilege Escalation FAQ Source: MITRE Type: CNA CVE-2003-0496 Source: BUGTRAQ Type: UNKNOWN 20030714 @stake named pipe exploit Source: BUGTRAQ Type: UNKNOWN 20030715 CreateFile exploit, (working) Source: ATSTAKE Type: Exploit, Patch, Vendor Advisory A070803-1 Source: CCN Type: Microsoft Windows 2000 Downloads Web site Windows 2000 Service Pack 4 Source: CCN Type: OSVDB ID: 10126 Microsoft SQL Server CreateFile API Function Privilege Escalation Source: CCN Type: BID-8128 Microsoft Windows CreateFile API Named Pipe Privilege Escalation Vulnerability Source: CCN Type: @stake, Inc. Security Advisory A070803-1 Named Pipe Filename Local Privilege Escalation Source: XF Type: UNKNOWN mssql-createfile-gain-privileges(12530) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |