4.6

CVE-2002-0643

The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Data Engine Version 1.0
Microsoft ≫ Sql Server Version 7.0
Microsoft ≫ Sql Server Version 7.0 Update sp1
Microsoft ≫ Sql Server Version 7.0 Update sp2
Microsoft ≫ Sql Server Version 7.0 Update sp3
Microsoft ≫ Sql Server Version 2000
Microsoft ≫ Sql Server Version 2000 Update sp1
Microsoft ≫ Sql Server Version 2000 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.7% 0.742
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=102640092826731&w=2
http://marc.info/?l=vuln-dev&m=102640394131103&w=2
http://www.kb.cert.org/vuls/id/338195
US Government Resource
http://www.securityfocus.com/bid/5203
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-035