First published: Tue Jul 23 2002(Updated: )
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server Data Engine (MSDE) | =2000 | |
Microsoft SQL Server | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0642 has a medium severity rating due to its potential for privilege escalation in Microsoft SQL Server 2000.
To fix CVE-2002-0642, you should adjust the permissions on the SQL Server service account registry keys to ensure they are not accessible to unauthorized users.
CVE-2002-0642 affects Microsoft SQL Server 2000 and Microsoft SQL Server Desktop Engine (MSDE) 2000.
Yes, CVE-2002-0642 can be exploited by local users who can access the insecure registry key to gain elevated privileges.
CVE-2002-0642 is categorized as a vulnerability related to incorrect permission settings on a registry key.