CVE-2002-1145: Critical severity microsoft sql server vulnerability

Published Oct 21, 2002
·
Updated

The xprunwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.

Affected Software

10 affected components
Microsoft SQL Server=7.0-sp1
Microsoft SQL Server=2000-sp2
Microsoft SQL Server=7.0
Microsoft Data Engine=1.0
Microsoft SQL Server=2000
Microsoft SQL Server=2000-sp1
Microsoft Data Engine=2000
Microsoft SQL Server=7.0-sp3
Microsoft SQL Server=7.0-sp4
Microsoft SQL Server=7.0-sp2

Event History

Oct 21, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2002-1145?

CVE-2002-1145 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive database operations.

2

How does CVE-2002-1145 impact Microsoft SQL Server?

CVE-2002-1145 allows any user to execute the xp_runwebtask stored procedure, which can compromise the security of the SQL Server instance.

3

How do I fix CVE-2002-1145?

To fix CVE-2002-1145, it is recommended to restrict execution permissions of the xp_runwebtask stored procedure to authorized users only.

4

Which versions of Microsoft SQL Server are affected by CVE-2002-1145?

CVE-2002-1145 affects Microsoft SQL Server 7.0 and 2000, including all service packs released until that time.

5

What are the consequences of an exploit using CVE-2002-1145?

Exploiting CVE-2002-1145 can lead to privilege escalation, allowing attackers to perform administrative tasks on the SQL Server environment.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203