Privilege Escalation Vulnerability in Microsoft SQL Server and MSDE

Reported October 17, 2002, by Microsoft.



·         Microsoft SQL Server 2000

·         Microsoft Desktop Engine (MSDE) 2000

·         Microsoft SQL Server 7.0

·         Microsoft Data Engine (MSDE) 1.0





A vulnerability exists in SQL Server that lets a low-privileged user run, delete, insert, and update Web tasks. This vulnerability stems from the fact that the xp_runwebtask stored procedure fails to set permissions properly when executed and runs under SQL Server's privileges. By default, PUBLIC users can execute the xp_runwebtask stored procedure, thus allowing privilege elevation. For more details about this vulnerability, see the discoverer’s Web site.




The vendor, Microsoft, has released Security Bulletin MS02-061 (Elevation of Privilege in SQL Server Web Tasks) to address this vulnerability and recommends that affected users apply the appropriate patch mentioned in the bulletin.



Discovered by David Litchfield of Next Generation Security Software Ltd.

Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.