peter bassill · operator
$ cve CVE-2002-0721 JSON

CVE-2002-0721 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 46.3% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS46.31% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2002-09-05
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftdata engine
microsoftsql server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD