← Vulnerability feed

Vulnerability record · CVE-2003-0150 · published 24 March 2003

CVE-2003-0150: MySQL world-writeable files allow privilege escalation to root

Oracle · Mysql

MySQL 3.23.55 and earlier creates world-writeable files and lets mysql users overwrite configuration files via the SELECT ... INTO OUTFILE operator. Overwriting my.cnf causes mysqld to run as root on restart, turning a database account into root on the host.

9.0 CVSS 2.0 High EPSS 45% · top 1.3%
9.0CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityAuthenticated remote privilege escalation to root with public exploit code and very high EPSS, though it requires a valid MySQL account and affects only legacy versions.

What it is

MySQL 3.23.55 and earlier creates world-writeable files and lets mysql users overwrite configuration files via the SELECT ... INTO OUTFILE operator. Overwriting my.cnf causes mysqld to run as root on restart, turning a database account into root on the host.

Impact

An attacker with a MySQL account gains root privileges on the underlying server, leading to full compromise of the host and any data or services on it.

Attack surface

Reached over the network via the MySQL protocol (AV:N) by an authenticated user with a valid mysql account (Au:S); no user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.448 (98.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code and active interest.

What to do

  • Upgrade MySQL to a version later than 3.23.55 or apply the vendor patch referenced in the advisories.
  • Do not run mysqld as root; run it under a dedicated unprivileged account and restrict file ownership.
  • Restrict FILE privilege and SELECT ... INTO OUTFILE usage to trusted administrative accounts only.
  • Audit and correct permissions on my.cnf and other MySQL configuration files so they are not world-writeable.
  • Monitor and alert on unexpected changes to MySQL configuration files.

Detection

  • Alert on modifications to my.cnf or other MySQL configuration files outside change windows.
  • Audit MySQL user privileges for FILE and OUTFILE usage and review accounts with those grants.
  • Search for files written by mysqld with world-writeable permissions in MySQL data and config directories.
  • Monitor for mysqld restarting with an unexpected effective UID of root.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000743
http://marc.info/?l=bugtraq&m=104715840202315&w=2
http://marc.info/?l=bugtraq&m=104739810523433&w=2
http://marc.info/?l=bugtraq&m=104800948128630&w=2
http://marc.info/?l=bugtraq&m=104802285012750&w=2
http://rhn.redhat.com/errata/RHSA-2003-094.html
http://www.debian.org/security/2003/dsa-303
http://www.kb.cert.org/vuls/id/203897 US Government Resource
http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:057
http://www.redhat.com/support/errata/RHSA-2003-093.html
http://www.securityfocus.com/bid/7052 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/11510
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A442
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000743
http://marc.info/?l=bugtraq&m=104715840202315&w=2
http://marc.info/?l=bugtraq&m=104739810523433&w=2
http://marc.info/?l=bugtraq&m=104800948128630&w=2
http://marc.info/?l=bugtraq&m=104802285012750&w=2
http://rhn.redhat.com/errata/RHSA-2003-094.html
http://www.debian.org/security/2003/dsa-303
http://www.kb.cert.org/vuls/id/203897 US Government Resource
http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:057
http://www.redhat.com/support/errata/RHSA-2003-093.html
http://www.securityfocus.com/bid/7052 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/11510
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A442

Track CVE-2003-0150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2750Oracle mysql vulnerabilityUnspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this …EPSS 3.6%10.0CVE-2004-0836Oracle mysql memory buffer overflow vulnerabilityBuffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of…EPSS 9.8%9.8CVE-2020-11656Sqlite use after free vulnerabilityIn SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…EPSS 7.6%9.8CVE-2019-14540Fasterxml jackson-databind deserialization of untrusted data vulnerabilityA Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.EPSS 11%9.8CVE-2016-9841Zlib vulnerabilityinffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.EPSS 7.6%9.8CVE-2016-9843Zlib vulnerabilityThe crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian C…EPSS 5.8%9.8CVE-2016-6662MySQL, MariaDB and Percona Server local privilege escalation via general_log_fileMySQL, MariaDB and Percona Server allow a local user to set general_log_file to a my.cnf configuration path, creating arbitrary configuration files a…EPSS 68%analysed9.8CVE-2016-0639Redhat enterprise linux vulnerabilityUnspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2003-0150), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.