CVE-2002-1123
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 78%
from disclosure to weapon0 days
Published on NVDSep 1
1st PoCAug 6
metasploitAug 5
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16398unverifiedexploitdbwww.exploit-db.com/exploits/21693unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=102873609025020&w=2http://online.securityfocus.com/archive/1/286220https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-056http://www.ciac.org/ciac/bulletins/n-003.shtmlhttp://www.iss.net/security_center/static/9788.phphttp://www.securityfocus.com/bid/5411