CVE-2003-0230: High severity Microsoft SQL Server vulnerability
Published Jul 25, 2003
·Updated
Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
Affected Software
12 affected components
Microsoft SQL Server=7.0-sp1
Microsoft SQL Server=2000-sp2
Microsoft SQL Server=7.0
Microsoft Data Engine=1.0
Microsoft SQL Server=2000-sp3
Microsoft SQL Server=2000
Microsoft SQL Server=2000-sp1
Microsoft SQL Server=2000-sp3a
Microsoft SQL Server=7.0-sp3
Microsoft SQL Server=2000
Microsoft SQL Server=7.0-sp4
Microsoft SQL Server=7.0-sp2
Event History
Jul 25, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0230?
CVE-2003-0230 has a medium severity level due to its potential for local privilege escalation.
2
How do I fix CVE-2003-0230?
To fix CVE-2003-0230, you should apply the patches provided by Microsoft relevant to the affected versions of SQL Server.
3
Which versions of SQL Server are affected by CVE-2003-0230?
CVE-2003-0230 affects Microsoft SQL Server versions 7.0, 2000, and MSDE, particularly the specified service packs.
4
Is named pipe hijacking a common vulnerability type like CVE-2003-0230?
Yes, named pipe hijacking is a known method of attacking local privilege escalation vulnerabilities.
5
Can CVE-2003-0230 be exploited remotely?
No, CVE-2003-0230 requires local access to exploit the vulnerability.