PT-2019-2695 · Microsoft · Sql Server

CVE-2019-1068

·

Publicado

2019-07-09

·

Atualizado

2026-08-29

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server versions 2014 through 2017
Description A remote code execution issue exists in Microsoft SQL Server due to incorrect handling of internal functions. This could allow an attacker to execute arbitrary code by sending a specially crafted SQL query. An attacker who successfully exploits this issue could execute code in the context of the SQL Server Database Engine service account. To exploit the issue, an authenticated attacker would need to submit a specially crafted query to an affected SQL server.
Recommendations For Microsoft SQL Server versions 2014 through 2017, update and patch all instances to address the issue. As a temporary workaround, consider restricting access to the SQL server to minimize the risk of exploitation. Avoid using specially crafted queries in the affected SQL server until the issue is resolved.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02582
CVE-2019-1068

Produtos afetados

Sql Server