Описание
Multiple serious vulnerabilities have been found in Microsoft SQL Server. Malicious users can exploit these vulnerabilities to gain privileges or obtain sensitive information.
Below is a complete list of vulnerabilities
- An improper pointer casting handling can be exploited by remotely authenticated attackers to gain privileges;
 - An improper request parameters validation at MDS can be exploited remotely via XSS attack to gain privileges;
 - Lack of parameters restrictions at Microsoft SQL Analysis Service can be exploited by remotely authenticated attacker to obtain sensitive information;
 - An improper ACL check at Microsoft SQL Server Agent can be exploited by remotely authenticated attackers to gain privileges.
 
Первичный источник обнаружения
Связанные продукты
Список CVE
- CVE-2016-7254 high
 - CVE-2016-7253 high
 - CVE-2016-7252 warning
 - CVE-2016-7251 warning
 - CVE-2016-7250 high
 - CVE-2016-7249 high
 
Список KB
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
                                    Нашли неточность в описании этой уязвимости? Дайте нам знать!