First published: Sat Jul 21 2001(Updated: )
An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =7.0 | |
Microsoft SQL Server | =2000-gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0344 is considered a moderate severity vulnerability that allows privilege escalation due to improper handling of cached connections.
To fix CVE-2001-0344, it's recommended to apply the latest service pack or update for Microsoft SQL Server 7.0 and 2000.
CVE-2001-0344 affects users of Microsoft SQL Server 7.0 and SQL Server 2000 Gold operating in Mixed Mode.
An attacker can exploit CVE-2001-0344 by reusing a cached connection of the sa administrator account to gain elevated privileges.
While CVE-2001-0344 is an older vulnerability, systems still running affected versions of SQL Server may still be at risk if not properly updated.