VULNERABILITY INTELLIGENCE

CVE-2002-2017

CVSS score10 HIGH
EPSS probability2.47%
CISA KEVNot currently listed
Published2002-12-31
Last modified2026-06-16

Description

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.