PT-2019-2695 · Microsoft · Sql Server
CVE-2019-1068
·
Publicado
2019-07-09
·
Atualizado
2026-08-29
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SQL Server versions 2014 through 2017
Description
A remote code execution issue exists in Microsoft SQL Server due to incorrect handling of internal functions. This could allow an attacker to execute arbitrary code by sending a specially crafted SQL query. An attacker who successfully exploits this issue could execute code in the context of the SQL Server Database Engine service account. To exploit the issue, an authenticated attacker would need to submit a specially crafted query to an affected SQL server.
Recommendations
For Microsoft SQL Server versions 2014 through 2017, update and patch all instances to address the issue.
As a temporary workaround, consider restricting access to the SQL server to minimize the risk of exploitation.
Avoid using specially crafted queries in the affected SQL server until the issue is resolved.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sql Server