Insecure Default Installation Process for Microsoft SQL Server

A vulnerability exists in SQL Server 2000 and SQL Server 7.0 (including MSDE 1.0) that can let an attacker compromise the vulnerable server.

Ken Pfeil

July 14, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported July 11, 2002, byMicrosoft.

VERSIONS AFFECTED

 

·        Microsoft SQL Server 2000, all editions.

·        Microsoft SQL Server 7.0, including Microsoft Data Engine (MSDE1.0)

 

DESCRIPTION

A vulnerability exists in SQLServer 2000 and SQL Server 7.0 (including MSDE 1.0) that can let an attackercompromise the vulnerable server. This vulnerability stems from the fact thatthe system stores the systems administrator password in the setup.iss and logfiles and doesn't remove the password when the installation is complete. Anyonecapable of doing an interactive logon can access this password and these files.

 

VENDOR RESPONSE

Thevendor, Microsoft, has released SecurityBulletin MS02-035(SQL Server Installation Process May Leave Password on System) to address thisvulnerability and recommends that affected users download and apply theappropriate patch mentioned in the bulletin. These patches are cumulative andaddress all previously discovered vulnerabilities in the affected product.

 

CREDIT
Discovered by CesarCerrudo and Mark Litchfieldof Next Generation Security Software.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like