Vulnerabilities > CVE-2003-0496 - Unspecified vulnerability in Microsoft Windows 2000 and Windows 2000 Terminal Services
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
exploit available
Summary
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 8 |
Exploit-Db
description Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)a. CVE-2003-0496 . Local exploit for windows platform id EDB-ID:22882 last seen 2016-02-02 modified 2003-07-08 published 2003-07-08 reporter Maceo source https://www.exploit-db.com/download/22882/ title Microsoft Windows 2000 - CreateFile API Named Pipe Privilege Escalation Vulnerability 1 description Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2). CVE-2003-0496. Local exploit for windows platform id EDB-ID:22883 last seen 2016-02-02 modified 2003-07-08 published 2003-07-08 reporter Maceo source https://www.exploit-db.com/download/22883/ title Microsoft Windows 2000 - CreateFile API Named Pipe Privilege Escalation Vulnerability 2
Seebug
bulletinFamily exploit description No description provided by source. id SSV:76676 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-76676 title Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2) bulletinFamily exploit description No description provided by source. id SSV:76675 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-76675 title Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0013.html
- http://marc.info/?l=bugtraq&m=105820282607865&w=2
- http://marc.info/?l=bugtraq&m=105820282607865&w=2
- http://marc.info/?l=bugtraq&m=105830986720243&w=2
- http://marc.info/?l=bugtraq&m=105830986720243&w=2
- http://www.atstake.com/research/advisories/2003/a070803-1.txt
- http://www.atstake.com/research/advisories/2003/a070803-1.txt