漏洞信息详情
Microsoft SQL Server / MSDE命名管道权限提升漏洞
- CNNVD编号:CNNVD-200308-197
- 危害等级: 高危
- CVE编号:
CVE-2003-0230
- 漏洞类型:
权限许可和访问控制
- 发布时间:
2003-08-27
- 威胁类型:
本地
- 更新时间:
2007-03-30
- 厂 商:
microsoft - 漏洞来源:
Microsoft -
漏洞简介
Microsoft SQL Server 7,2000版本和MSDE存在漏洞。本地用户可以通过另一个用户认证时劫持已命名管道提升特权,也称为\”Named Pipe Hijacking\”漏洞。
漏洞公告
The vendor has released a fix to address this issue.
Microsoft SQL Server 2000 SP3
-
Microsoft SQL2000-KB815495-8.00.0818-ENU.exeSQL Server 2000 64-bit
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E8
6-8F2E-CB1BD3A6A44B&displaylang=en -
Microsoft SQL2000-KB815495-8.00.0818-ENU.exeSQL Server 2000 32-bit
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C
5-ADD3-B8C99618E68D&displaylang=en
Microsoft SQL Server 2000 Desktop Engine
-
Microsoft SQL2000-KB815495-8.00.0818-ENU.exeSQL Server 2000 64-bit
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E8
6-8F2E-CB1BD3A6A44B&displaylang=en -
Microsoft SQL2000-KB815495-8.00.0818-ENU.exeSQL Server 2000 32-bit
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C
5-ADD3-B8C99618E68D&displaylang=en
Microsoft SQL Server 2000 SP3a
-
Microsoft SQL2000-KB815495-8.00.0818-ENU.exeSQL Server 2000 64-bit
http://microsoft.com/downloads/details.aspx?FamilyId=72336508-057A-4E8
6-8F2E-CB1BD3A6A44B&displaylang=en -
Microsoft SQL2000-KB815495-8.00.0818-ENU.exeSQL Server 2000 32-bit
http://microsoft.com/downloads/details.aspx?FamilyId=9814AE9D-BD44-40C
5-ADD3-B8C99618E68D&displaylang=en
Microsoft Data Engine 1.0
-
Microsoft SQL70-KB815495-v7.00.1094-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=FE5B0892-A5C9-44C
2-9B42-0D291E9C1636&displaylang=en
Microsoft SQL Server 7.0 SP4
-
Microsoft SQL70-KB815495-v7.00.1094-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=FE5B0892-A5C9-44C
2-9B42-0D291E9C1636&displaylang=en
参考网址
来源:US-CERT Vulnerability Note: VU#556356
名称: VU#556356
链接:http://www.kb.cert.org/vuls/id/556356
来源: MS
名称: MS03-031
链接:http://www.microsoft.com/technet/security/bulletin/MS03-031.asp
来源: US Government Resource: oval:org.mitre.oval:def:235
名称: oval:org.mitre.oval:def:235
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:235
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END