CVE-1999-1556

Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:sql_server:6.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:31

Type Values Removed Values Added
References () http://marc.info/?l=ntbugtraq&m=90222453431645&w=2 - () http://marc.info/?l=ntbugtraq&m=90222453431645&w=2 -
References () http://www.securityfocus.com/bid/109 - Vendor Advisory () http://www.securityfocus.com/bid/109 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7354 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7354 -

Information

Published : 1998-06-29 04:00

Updated : 2024-11-20 23:31


NVD link : CVE-1999-1556

Mitre link : CVE-1999-1556

CVE.ORG link : CVE-1999-1556


JSON object : View

Products Affected

microsoft

  • sql_server