peter bassill · operator
$ cve CVE-2000-1209 JSON

CVE-2000-1209 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 87.3% (pctl 100)

Patch early

A public exploit exists.

Description

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS87.31% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2002-08-12
Last modified2026-06-16

Affected (4)

VendorProduct
compaqinsight manager
compaqinsight manager xe
microsoftdata engine
microsoftmsde

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD