CVE-2002-0721

N/A Unknown
Published: September 05, 2002 Modified: April 16, 2026
View on NVD

Description

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.kb.cert.org/vuls/id/399531
Source: cve@mitre.org
US Government Resource
http://www.kb.cert.org/vuls/id/818939
Source: cve@mitre.org
US Government Resource
http://www.kb.cert.org/vuls/id/939675
Source: cve@mitre.org
US Government Resource
http://marc.info/?l=bugtraq&m=102950473002959&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=ntbugtraq&m=102950792606475&w=2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.kb.cert.org/vuls/id/399531
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.kb.cert.org/vuls/id/818939
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.kb.cert.org/vuls/id/939675
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.ngssoftware.com/advisories/mssql-esppu.txt
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
47.9%
98th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

microsoft