CVE-2003-0496
HIGH 7.2EPSS 4.6%
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 4.57% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2003-07-10
- Updated
- 2024-08-08