7.5

CVE-2002-1138

Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftData Engine Version1.0
MicrosoftData Engine Version2000
MicrosoftSql Server Version7.0
MicrosoftSql Server Version7.0 Updatesp1
MicrosoftSql Server Version7.0 Updatesp2
MicrosoftSql Server Version7.0 Updatesp3
MicrosoftSql Server Version7.0 Updatesp4
MicrosoftSql Server Version2000
MicrosoftSql Server Version2000 Updatesp1
MicrosoftSql Server Version2000 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 11.4% 0.929
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P