CVE

Id
7762  
CVE No.
CVE-2003-0938  
Status
Candidate  
Description
vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.  
Phase
Assigned (20031111)  
Votes
None (candidate not yet proposed)  
Comments