TUCoPS :: Web :: Apps :: web5636.htm

SQL user priviledge escalation via stored procedures
16th Aug 2002 [SBWID-5636]
COMMAND

	SQL user priviledge escalation via stored procedures

SYSTEMS AFFECTED

	Microsoft SQL Server 2000 and 7

PROBLEM

	David Litchfield [david@ngssoftware.com] posted  an  advisory  where  he
	reveals  that  the   three   stored   procedures   :   xp_execresultset,
	xp_printstatements and xp_displayparamstmt can be used  to  escalate  an
	SQL session authenticated by Windows basic mechanism to  the  SQL  power
	users :
	

	http://www.nextgenss.com/advisories/mssql-esppu.txt

	

SOLUTION

	See:
	

	http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-043.asp

	

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH