The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
http://www.securityfocus.com/bid/5511
http://www.iss.net/security_center/static/9908.php
http://online.securityfocus.com/archive/1/288105
Source: Mitre, NVD
Published: 2002-12-31
Updated: 2019-10-07
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical