CVE-2002-0624 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 22.8% (pctl 98)
Patch early
A public exploit exists.
Description
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 22.85% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-07-23 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | msde |
| microsoft | sql server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft SQL Server 2000 - Password Encrypt procedure Buffer Overflow | 2002-06-14 |
References
- http://www.cert.org/advisories/CA-2002-22.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A291
- http://www.cert.org/advisories/CA-2002-22.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A291
→ the Explorer · watch your stack · NVD