Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2002-0643

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2002-0643
Last Modified 10 Sep 2008 03:12:38
Published 23 Jul 2002 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2002-0643

Summary

The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."

Vulnerable Systems

Application

  • Microsoft Data Engine 1.0

  • Microsoft Sql Server 2000

  • Microsoft Sql Server 7.0


References

CERT-VN - VU#338195

MS - MS02-035

BUGTRAQ - 20020711 SQL Server 7 & 2000 Installation process and Service Packs write encoded passwords to a file

BID - 5203


Last Updated: 27 May 2016 10:37:00