Microsoft SQL Server Privilege Escalation Vulnerability via Command Injection

Vulnerability

A command injection vulnerability has been identified in Microsoft SQL Server, allowing an authorized attacker to elevate privileges over a network. This issue arises from improper neutralization of special elements used in commands, enabling the injection and execution of SQL code with elevated rights, particularly sysadmin privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain sysadmin rights on the affected SQL Server instance.

Remediation

Users can apply the security update for their specific version of SQL Server. Detailed update instructions are available in the Microsoft Security Update Guide. For SQL Server 2022, 2019, 2017, and 2016, security updates can be downloaded from the Microsoft Download Center.

Added: Sep 9, 2025, 5:50 PM
Updated: Sep 9, 2025, 5:50 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
7.5
exploitability
4.9
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.