← Vulnerability feed

Vulnerability record · CVE-2000-1209 · published 12 August 2002

CVE-2000-1209: Microsoft SQL Server and MSDE default null sa password

CCompaq · Insight Manager

Microsoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumbleweed Secure Mail, Compaq Insight Manager and Visio 2000 ship these products in that state. Because sa is the highest-privilege database account, any remote attacker who can reach the database listener can log in with no credentials and take full control of the instance.

10.0 CVSS 2.0 High EPSS 87% · top 0.2%
10.0CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote access to the highest-privilege database account with a CVSS 2.0 score of 10 and confirmed worm exploitation makes this a top-priority exposure wherever affected instances remain reachable.

What it is

Microsoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumbleweed Secure Mail, Compaq Insight Manager and Visio 2000 ship these products in that state. Because sa is the highest-privilege database account, any remote attacker who can reach the database listener can log in with no credentials and take full control of the instance.

Impact

An attacker gains full administrative privileges over the database server, allowing data theft, modification or deletion, and execution of operating system commands through SQL Server facilities. Worms such as Voyager Alpha Force and Spida used exactly this access to spread.

Attack surface

Reachable over the network against the SQL Server or MSDE listener; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are required. Any host exposing the database port to untrusted networks is exposed.

Exploitation

Exploitation is confirmed in the wild by named worms (Voyager Alpha Force, Spida) per the description, and EPSS is very high at 0.873 (99.7th percentile), though the CVE is not listed in CISA KEV. Reference tags include Patch and Vendor Advisory but no exploit tag.

What to do

  • Apply the vendor fixes referenced in MS02-020 and the Microsoft KB articles (Q313418, Q321081) and upgrade off SQL Server 7.0/2000 and MSDE 1.0 where possible.
  • Set a strong non-null password for the sa account and any other accounts with blank or default passwords.
  • Disable or rename the sa account and use Windows authentication or least-privilege accounts for applications.
  • Block database ports (TCP 1433/1434 and named-instance ports) from untrusted networks with host and network firewalls.
  • Audit third-party products that bundle MSDE, such as Tumbleweed Secure Mail, Compaq Insight Manager and Visio 2000, for the same default configuration.

Detection

  • Search SQL Server and MSDE logs for successful sa logons from unexpected or external source addresses.
  • Scan the environment for database instances accepting blank or default sa credentials and for hosts exposing 1433/1434 to untrusted networks.
  • Monitor for SQL Server processes spawning command shells or writing unexpected files, which indicates sa-level abuse.
  • Alert on the worm-related artifacts and traffic patterns associated with Voyager Alpha Force and Spida.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-1209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed10.0CVE-2001-0840Compaq insight manager xe vulnerabilityBuffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.EPSS 9.0%10.0CVE-2001-0134Compaq armada insight manager vulnerabilityBuffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents a…EPSS 4.0%9.0CVE-2008-0086Microsoft SQL Server 2000 convert function buffer overflowA buffer overflow exists in the convert function of Microsoft SQL Server 2000 SP4, MSDE 2000 SP4, and WMSDE. A remote authenticated user can trigger …EPSS 62%analysed9.0CVE-2008-0106Microsoft data engine memory buffer overflow vulnerabilityBuffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrar…EPSS 35%9.0CVE-2008-0107Microsoft data engine vulnerabilityInteger underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 …EPSS 35%7.5CVE-2002-1137Microsoft data engine vulnerabilityBuffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine…EPSS 9.4%

Source: NIST National Vulnerability Database (record CVE-2000-1209), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.