Vulnerability record · CVE-2003-0150 · published 24 March 2003
CVE-2003-0150: MySQL world-writeable files allow privilege escalation to root
Oracle · Mysql
MySQL 3.23.55 and earlier creates world-writeable files and lets mysql users overwrite configuration files via the SELECT ... INTO OUTFILE operator. Overwriting my.cnf causes mysqld to run as root on restart, turning a database account into root on the host.
Description
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityAuthenticated remote privilege escalation to root with public exploit code and very high EPSS, though it requires a valid MySQL account and affects only legacy versions.
What it is
MySQL 3.23.55 and earlier creates world-writeable files and lets mysql users overwrite configuration files via the SELECT ... INTO OUTFILE operator. Overwriting my.cnf causes mysqld to run as root on restart, turning a database account into root on the host.
Impact
An attacker with a MySQL account gains root privileges on the underlying server, leading to full compromise of the host and any data or services on it.
Attack surface
Reached over the network via the MySQL protocol (AV:N) by an authenticated user with a valid mysql account (Au:S); no user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.448 (98.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code and active interest.
What to do
- Upgrade MySQL to a version later than 3.23.55 or apply the vendor patch referenced in the advisories.
- Do not run mysqld as root; run it under a dedicated unprivileged account and restrict file ownership.
- Restrict FILE privilege and SELECT ... INTO OUTFILE usage to trusted administrative accounts only.
- Audit and correct permissions on my.cnf and other MySQL configuration files so they are not world-writeable.
- Monitor and alert on unexpected changes to MySQL configuration files.
Detection
- Alert on modifications to my.cnf or other MySQL configuration files outside change windows.
- Audit MySQL user privileges for FILE and OUTFILE usage and review accounts with those grants.
- Search for files written by mysqld with world-writeable permissions in MySQL data and config directories.
- Monitor for mysqld restarting with an unexpected effective UID of root.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0150 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0150), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.