CVE-2002-0641: Buffer Overflow
Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0641?
CVE-2002-0641 has been rated as a critical vulnerability due to the ability for attackers to execute arbitrary code with database administration privileges.
How do I fix CVE-2002-0641?
To mitigate CVE-2002-0641, it is recommended to apply the latest security patches for Microsoft SQL Server 2000 and restrict access to the BULK INSERT functionality.
Who is affected by CVE-2002-0641?
CVE-2002-0641 primarily affects users of Microsoft SQL Server 2000 and Microsoft SQL Server Desktop Engine (MSDE) 2000 with database administration privileges.
What type of attack does CVE-2002-0641 enable?
CVE-2002-0641 enables attackers to exploit a buffer overflow vulnerability to execute arbitrary code on the affected SQL Server instances.
Is CVE-2002-0641 exploitable remotely?
CVE-2002-0641 is not exploitable remotely unless the attacker has database administration privileges on the affected SQL Server instance.