Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
Use Microsoft vendor hub and Data Engine product page to widen CVE-2002-0721 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2002-1145, CVE-2008-0107 and CVE-2008-0106 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.