Beschreibung
Multiple serious vulnerabilities have been found in Microsoft SQL Server. Malicious users can exploit these vulnerabilities to gain privileges or obtain sensitive information.
Below is a complete list of vulnerabilities
- An improper pointer casting handling can be exploited by remotely authenticated attackers to gain privileges;
- An improper request parameters validation at MDS can be exploited remotely via XSS attack to gain privileges;
- Lack of parameters restrictions at Microsoft SQL Analysis Service can be exploited by remotely authenticated attacker to obtain sensitive information;
- An improper ACL check at Microsoft SQL Server Agent can be exploited by remotely authenticated attackers to gain privileges.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2016-7254 critical
- CVE-2016-7253 critical
- CVE-2016-7252 critical
- CVE-2016-7251 critical
- CVE-2016-7250 critical
- CVE-2016-7249 critical
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!