Microsoft SQL Server
cpe:2.3:a:microsoft:sql_server:*:*:*:*:*:*:*
A command injection vulnerability has been identified in Microsoft SQL Server, allowing an authorized attacker to elevate privileges over a network. This issue arises from improper neutralization of special elements used in commands, enabling the injection and execution of SQL code with elevated rights, particularly sysadmin privileges.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain sysadmin rights on the affected SQL Server instance.
Users can apply the security update for their specific version of SQL Server. Detailed update instructions are available in the Microsoft Security Update Guide. For SQL Server 2022, 2019, 2017, and 2016, security updates can be downloaded from the Microsoft Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.