Описание
Multiple serious vulnerabilities have been found in Microsoft SQL Server. Malicious users can exploit these vulnerabilities to gain privileges or obtain sensitive information.
Below is a complete list of vulnerabilities
- An improper pointer casting handling can be exploited by remotely authenticated attackers to gain privileges;
- An improper request parameters validation at MDS can be exploited remotely via XSS attack to gain privileges;
- Lack of parameters restrictions at Microsoft SQL Analysis Service can be exploited by remotely authenticated attacker to obtain sensitive information;
- An improper ACL check at Microsoft SQL Server Agent can be exploited by remotely authenticated attackers to gain privileges.
Первичный источник обнаружения
Связанные продукты
Список CVE
- CVE-2016-7254 high
- CVE-2016-7253 high
- CVE-2016-7252 warning
- CVE-2016-7251 warning
- CVE-2016-7250 high
- CVE-2016-7249 high
Список KB
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!