Back
CVE-2003-0230
Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
Published: Aug 27, 2003
Modified: Jun 16, 2026
CWE-264
CVSS Metrics
Affected Products (12)
| Vendor | Product | Version |
|---|---|---|
| microsoft | data_engine | 1.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 7.0 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
| microsoft | sql_server | 2000 |
GitHub Security Advisory GHSA-q8hv-377q-25pw
Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named...
References (6)
- http://www.kb.cert.org/vuls/id/556356 US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A235
- http://www.kb.cert.org/vuls/id/556356 US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-031
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A235
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
2.26%
Top 19% most likely to be exploited
Threat Score
29.5 / 100
Data Sources
NVD
EPSS
GitHub