Vulnerability record · CVE-2002-0186 · published 3 July 2002
CVE-2002-0186: Microsoft SQL Server 2000 SQLXML ISAPI buffer overflow
Microsoft · Sql Server
The SQLXML ISAPI extension in Microsoft SQL Server 2000 contains an unchecked buffer that overflows when a data query supplies an overly long content-type parameter. Because the flaw is remotely reachable and unauthenticated, it exposes any server running the affected extension to code execution. The record does not list specific affected builds beyond SQL Server 2000.
Description
Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a high EPSS score, though the product is legacy and no KEV listing or known exploit tag is present.
What it is
The SQLXML ISAPI extension in Microsoft SQL Server 2000 contains an unchecked buffer that overflows when a data query supplies an overly long content-type parameter. Because the flaw is remotely reachable and unauthenticated, it exposes any server running the affected extension to code execution. The record does not list specific affected builds beyond SQL Server 2000.
Impact
A remote attacker can execute arbitrary code in the context of the SQLXML ISAPI extension, potentially taking over the database server. Partial confidentiality, integrity and availability impact is reflected in the CVSS 2.0 vector.
Attack surface
Reached over the network via HTTP requests to the SQLXML ISAPI endpoint, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.55455 (99th percentile), indicating high modeled likelihood of exploitation. Reference tags include Patch and Vendor Advisory, with no public exploit tag present.
What to do
- Apply Microsoft Security Bulletin MS02-030, which addresses this vulnerability.
- Disable or remove the SQLXML ISAPI extension if it is not required.
- Restrict network access to the SQLXML ISAPI endpoint to trusted hosts only.
- Monitor vendor guidance for any additional configuration hardening for SQL Server 2000.
Detection
- Inspect web server and SQLXML ISAPI logs for requests with abnormally long content-type headers.
- Alert on crashes or restarts of the SQLXML ISAPI process or IIS worker process.
- Hunt for unexpected child processes spawned by the SQL Server or IIS service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0186 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0186), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.