Reported October 17, 2002, by Microsoft.
VERSIONS AFFECTED
· Microsoft SQL Server 2000
· Microsoft Desktop Engine (MSDE) 2000
· Microsoft SQL Server 7.0
· Microsoft Data Engine (MSDE) 1.0
DESCRIPTION
A vulnerability exists in SQL Server that lets a low-privileged user run, delete, insert, and update Web tasks. This vulnerability stems from the fact that the xp_runwebtask stored procedure fails to set permissions properly when executed and runs under SQL Server's privileges. By default, PUBLIC users can execute the xp_runwebtask stored procedure, thus allowing privilege elevation. For more details about this vulnerability, see the discoverer’s Web site.
VENDOR RESPONSE
The vendor, Microsoft, has released Security Bulletin MS02-061 (Elevation of Privilege in SQL Server Web Tasks) to address this vulnerability and recommends that affected users apply the appropriate patch mentioned in the bulletin.
CREDIT
Discovered by David Litchfield of Next Generation Security Software Ltd.