Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2002.582 -- Microsoft Security Bulletin MS02-061 Elevation of Privilege in SQL Server Web Tasks (Q316333) 17 October 2002 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Microsoft SQL Server 7.0 Microsoft SQL Server 2000 Microsoft Data Engine (MSDE) 1.0 Microsoft Desktop Engine (MSDE) 2000 Vendor: Microsoft Operating System: Windows Impact: Execute Arbitrary Code/Commands Increased Privileges Access Required: Remote Existing Account Ref: ESB-2002.539 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- - - ---------------------------------------------------------------------- Title: Elevation of Privilege in SQL Server Web Tasks (Q316333) Released: 16 October 2002 Software: Microsoft SQL Server 7.0 and 2000 Impact: Elevation of privilege Max Risk: Critical Bulletin: MS02-061 Microsoft encourages customers to review the Security Bulletin at: http://www.microsoft.com/technet/security/bulletin/MS02-061.asp. - - ---------------------------------------------------------------------- Issue: ====== SQL Server 7.0 and 2000 provide stored procedures which is a coll- ection of Transact-SQL statements stored under a name and processed as a group. One stored procedure, an extended stored procedure and weak permissions on a table combine to allow a low privileged user the ability to run, delete, insert or update web tasks. An attacker who is able to authenticate to a SQL server could delete, insert or update all the web tasks created by other users. In addition, the attacker could run already created web tasks in the context of the creator of the web task. This typically runs in the context of the SQL Server Agent service account. Mitigating Factors: ==================== - - - It is necessary to be an authenticated user of the SQL Server. - - - Exploiting this vulnerability could allow the attacker to escalate privileges to the level of the SQL Server service account. By default, the service runs with the privileges of a domain user, rather than with system privileges. - - - Web tasks have to exist in the first place. Risk Rating: ============ - Internet systems: Critical - Intranet systems: Critical - Client systems: None Patch Availability: =================== - A patch is available to fix this vulnerability. Please read the Security Bulletin at http://www.microsoft.com/technet/security/bulletin/ms02-061.asp for information on obtaining this patch. Acknowledgment: =============== - Microsoft thanks David Litchfield of Next Generation Security Software Ltd. for reporting this issue to us and working with us to protect customers. We would also like to thank Martin Rakhmanoff (jimmers@yandex.ru) for contributing to the investigation. - - --------------------------------------------------------------------- THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY. - -----BEGIN PGP SIGNATURE----- Version: PGP 7.1 iQEVAwUBPa3z6Y0ZSRQxA/UrAQFWOQf/YE4HJMZ7ez1BC9n3W2DRI9BpQVGw2s4N ALAcn2EprvU+jh4GUAuO9DilsNS/QjSsox6SFszjKJQih48xZTTXqnAocexC/8QV iK0x97xnqGA7+zgM7XGyKnUIOaEJZzTLyvY/qY5gmWZRTyqQsDrO+xUN3JecgPsU EYIkCINtLC51tRbFdK0NE3wlARcmamXFbkkm0ZeHh/ogh4pyLvXhHnabGPYMDuoB 2CDzOGpbMaI+PNRF2ZaVS4BlDfvR1jutizBQ9420HreFc7A6CWhu4WECtQzlHVNX r+WnaC3PidLv8tYAMFnHf7Y1hU/1w/l/R0MK2+oOn/JKsWnB7bgG1w== =FwnJ - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to use any or all of this information is the responsibility of each user or organisation, and should be done so in accordance with site policies and procedures. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the original authors to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/Information/advisories.html If you believe that your system has been compromised, contact AusCERT or your representative in FIRST (Forum of Incident Response and Security Teams). Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. -----BEGIN PGP SIGNATURE----- Version: 2.6.3i Charset: noconv Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key iQCVAwUBPa75Pyh9+71yA2DNAQE8eAP+L0pZJOoz3Dm1yHHu2ib2TWlwUGeZ5Pc1 oL3k9CxosJVBkEGHOdW7p3ewInOrz8RwkL1c/3KBdMd22Kp9ISdV7ADhzHjbF2+6 Rz37ysRjmObYmZGQz4an33dqv8l8JGJsYWu2q7iit8nJUr81HkT6e8RhNOkfGvws aHTTn6UIstQ= =PwP1 -----END PGP SIGNATURE-----