CVE-2003-0496

Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.

Scoring

CVSS base score
0.09
EPSS probability
2.18%
Published
2003-07-10
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs