CVE-2000-1209 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 87.3% (pctl 100)
Patch early
A public exploit exists.
Description
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 87.31% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-08-12 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| compaq | insight manager |
| compaq | insight manager xe |
| microsoft | data engine |
| microsoft | msde |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft SQL Server - Payload Execution (via SQL Injection) (Metasploit) | 2011-02-08 |
| exploit-db | Microsoft SQL Server - Payload Execution (Metasploit) | 2010-12-21 |
References
- http://marc.info/?l=bugtraq&m=96333895000350&w=2
- http://marc.info/?l=bugtraq&m=96593218804850&w=2
- http://marc.info/?l=bugtraq&m=96644570412692&w=2
- http://online.securityfocus.com/archive/1/273639
- http://security-archive.merton.ox.ac.uk/bugtraq-200008/0233.html
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ313418
- http://support.microsoft.com/default.aspx?scid=kb%3BEN-US%3Bq321081
- http://www.iss.net/security_center/static/1459.php
- http://www.kb.cert.org/vuls/id/635463
- http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp
- http://www.osvdb.org/3570
- http://www.securityfocus.com/bid/4797
- http://marc.info/?l=bugtraq&m=96333895000350&w=2
- http://marc.info/?l=bugtraq&m=96593218804850&w=2
- http://marc.info/?l=bugtraq&m=96644570412692&w=2
- http://online.securityfocus.com/archive/1/273639
- http://security-archive.merton.ox.ac.uk/bugtraq-200008/0233.html
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ313418
- http://support.microsoft.com/default.aspx?scid=kb%3BEN-US%3Bq321081
- http://www.iss.net/security_center/static/1459.php
→ the Explorer · watch your stack · NVD