Privilege Escalation Vulnerability in Microsoft SQL Server and MSDE
A vulnerability exists in SQL Server that lets a low-privileged user run, delete, insert, and update Web tasks.
October 20, 2002
Reported October 17, 2002, byMicrosoft.
VERSIONS AFFECTED
· Microsoft SQL Server 2000
· Microsoft Desktop Engine (MSDE) 2000
· Microsoft SQL Server 7.0
· Microsoft Data Engine (MSDE) 1.0
DESCRIPTION
A vulnerability exists in SQL Server that lets alow-privileged user run, delete, insert, and update Web tasks.This vulnerability stems from the fact that the xp_runwebtask stored procedure fails to set permissionsproperly when executed and runs under SQL Server's privileges. By default,PUBLIC users can execute the xp_runwebtask stored procedure, thus allowingprivilege elevation. For more details about this vulnerability, see thediscoverer’s Website.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-061(Elevation of Privilege in SQL Server Web Tasks) to address this vulnerabilityand recommends that affected users apply the appropriate patch mentioned in thebulletin.
CREDIT
Discoveredby David Litchfield of Next GenerationSecurity Software Ltd.
Read more about:
MicrosoftAbout the Author
You May Also Like