CVE detail
CVE-2003-0148 — CVE-2003-0148
Published 2003-08-27 · Modified 2026-06-16 · Vendor mcafee · Product epolicy_orchestrator · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0056
EPSS probability
exploitation probability, 30d
43.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References