← Vulnerability feed

Vulnerability record · CVE-2002-0186 · published 3 July 2002

CVE-2002-0186: Microsoft SQL Server 2000 SQLXML ISAPI buffer overflow

Microsoft · Sql Server

The SQLXML ISAPI extension in Microsoft SQL Server 2000 contains an unchecked buffer that overflows when a data query supplies an overly long content-type parameter. Because the flaw is remotely reachable and unauthenticated, it exposes any server running the affected extension to code execution. The record does not list specific affected builds beyond SQL Server 2000.

7.5 CVSS 2.0 High EPSS 55% · top 1.0%
7.5CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with a high EPSS score, though the product is legacy and no KEV listing or known exploit tag is present.

What it is

The SQLXML ISAPI extension in Microsoft SQL Server 2000 contains an unchecked buffer that overflows when a data query supplies an overly long content-type parameter. Because the flaw is remotely reachable and unauthenticated, it exposes any server running the affected extension to code execution. The record does not list specific affected builds beyond SQL Server 2000.

Impact

A remote attacker can execute arbitrary code in the context of the SQLXML ISAPI extension, potentially taking over the database server. Partial confidentiality, integrity and availability impact is reflected in the CVSS 2.0 vector.

Attack surface

Reached over the network via HTTP requests to the SQLXML ISAPI endpoint, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.55455 (99th percentile), indicating high modeled likelihood of exploitation. Reference tags include Patch and Vendor Advisory, with no public exploit tag present.

What to do

  • Apply Microsoft Security Bulletin MS02-030, which addresses this vulnerability.
  • Disable or remove the SQLXML ISAPI extension if it is not required.
  • Restrict network access to the SQLXML ISAPI endpoint to trusted hosts only.
  • Monitor vendor guidance for any additional configuration hardening for SQL Server 2000.

Detection

  • Inspect web server and SQLXML ISAPI logs for requests with abnormally long content-type headers.
  • Alert on crashes or restarts of the SQLXML ISAPI process or IIS worker process.
  • Hunt for unexpected child processes spawned by the SQL Server or IIS service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0186 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0618Microsoft SQL Server Reporting Services ViewState deserialization RCESQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can…KEVEPSS 99%analysed8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed9.8CVE-2018-8273Microsoft sql server out-of-bounds write vulnerabilityA buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…EPSS 29%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%9.3CVE-2009-2501Microsoft windows 2003 server memory buffer overflow vulnerabilityHeap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Offic…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2002-0186), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.