← Vulnerability feed

Vulnerability record · CVE-2002-1123 · published 24 September 2002

CVE-2002-1123: Microsoft SQL Server 2000 authentication buffer overflow (Hello overflow)

Microsoft · Data Engine

The authentication function in Microsoft SQL Server 2000 and MSDE 2000 contains a buffer overflow reachable through a long request sent to TCP port 1433, known as the "Hello" overflow. A remote, unauthenticated attacker can trigger it before authentication completes, making it a pre-auth code execution flaw in a widely deployed database service.

7.5 CVSS 2.0 High EPSS 78% · top 0.4%
7.5CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityPre-authentication remote code execution on a network-exposed database service with a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

The authentication function in Microsoft SQL Server 2000 and MSDE 2000 contains a buffer overflow reachable through a long request sent to TCP port 1433, known as the "Hello" overflow. A remote, unauthenticated attacker can trigger it before authentication completes, making it a pre-auth code execution flaw in a widely deployed database service.

Impact

An attacker can execute arbitrary code with the privileges of the SQL Server service, potentially leading to full host compromise and data theft or destruction.

Attack surface

Reachable over the network via TCP port 1433 with no authentication required, since the flaw is in the authentication handshake itself. No user interaction is needed; the vector is AV:N/AC:L/Au:N.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.777, 99.5th percentile), indicating strong likelihood of exploitation activity. Reference tags include only a Vendor Advisory, with no public exploit tag supplied.

What to do

  • Apply the Microsoft security bulletin MS02-056 update for SQL Server 2000 and MSDE 2000.
  • Block or restrict TCP port 1433 from untrusted networks with host and perimeter firewalls.
  • Disable or remove MSDE 2000 instances that are not required, and avoid exposing database services directly to the internet.
  • Run the SQL Server service under a low-privilege account to limit the impact of successful code execution.
  • Monitor vendor advisories for any updated guidance, since the record is old and product version detail is absent.

Detection

  • Inspect network traffic to TCP port 1433 for oversized or malformed authentication/Hello requests.
  • Alert on unexpected SQL Server service crashes or restarts, which can indicate failed exploitation attempts.
  • Monitor for suspicious child processes or command execution spawned by the SQL Server service account.
  • Review firewall and IDS logs for scanning or connection attempts against port 1433 from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0618Microsoft SQL Server Reporting Services ViewState deserialization RCESQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can…KEVEPSS 99%analysed8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed10.0CVE-2000-1209Microsoft SQL Server and MSDE default null sa passwordMicrosoft SQL Server 2000, SQL Server 7.0 and MSDE 1.0 install the "sa" account with a default null password, and third-party packages such as Tumble…EPSS 87%analysed9.8CVE-2018-8273Microsoft sql server out-of-bounds write vulnerabilityA buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…EPSS 29%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2002-1123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.