VULNERABILITY INTELLIGENCE
CVE-2002-2017
CVSS score10 HIGH
EPSS probability2.47%
CISA KEVNot currently listed
Published2002-12-31
Last modified2026-06-16
Description
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.