Vulnerability record · CVE-2000-1209 · published 12 August 2002
CVE-2000-1209: Microsoft SQL Server and MSDE default null sa password
CCompaq · Insight Manager
Microsoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumbleweed Secure Mail, Compaq Insight Manager and Visio 2000 ship these products in that state. Because sa is the highest-privilege database account, any remote attacker who can reach the database listener can log in with no credentials and take full control of the instance.
Description
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote access to the highest-privilege database account with a CVSS 2.0 score of 10 and confirmed worm exploitation makes this a top-priority exposure wherever affected instances remain reachable.
What it is
Microsoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumbleweed Secure Mail, Compaq Insight Manager and Visio 2000 ship these products in that state. Because sa is the highest-privilege database account, any remote attacker who can reach the database listener can log in with no credentials and take full control of the instance.
Impact
An attacker gains full administrative privileges over the database server, allowing data theft, modification or deletion, and execution of operating system commands through SQL Server facilities. Worms such as Voyager Alpha Force and Spida used exactly this access to spread.
Attack surface
Reachable over the network against the SQL Server or MSDE listener; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are required. Any host exposing the database port to untrusted networks is exposed.
Exploitation
Exploitation is confirmed in the wild by named worms (Voyager Alpha Force, Spida) per the description, and EPSS is very high at 0.873 (99.7th percentile), though the CVE is not listed in CISA KEV. Reference tags include Patch and Vendor Advisory but no exploit tag.
What to do
- Apply the vendor fixes referenced in MS02-020 and the Microsoft KB articles (Q313418, Q321081) and upgrade off SQL Server 7.0/2000 and MSDE 1.0 where possible.
- Set a strong non-null password for the sa account and any other accounts with blank or default passwords.
- Disable or rename the sa account and use Windows authentication or least-privilege accounts for applications.
- Block database ports (TCP 1433/1434 and named-instance ports) from untrusted networks with host and network firewalls.
- Audit third-party products that bundle MSDE, such as Tumbleweed Secure Mail, Compaq Insight Manager and Visio 2000, for the same default configuration.
Detection
- Search SQL Server and MSDE logs for successful sa logons from unexpected or external source addresses.
- Scan the environment for database instances accepting blank or default sa credentials and for hosts exposing 1433/1434 to untrusted networks.
- Monitor for SQL Server processes spawning command shells or writing unexpected files, which indicates sa-level abuse.
- Alert on the worm-related artifacts and traffic patterns associated with Voyager Alpha Force and Spida.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-1209 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-1209), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.