← back
CVE-2000-1209

CVE-2000-1209

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 87%
from disclosure to weapon3055 days
Published on NVDAug 10
1st PoC+3055d
metasploitMay 30
exploitation probability
87%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.