Security
Headlines
HeadlinesLatestCVEs

Tag

#SQL Server

CVE-2023-21705: Microsoft SQL Server Remote Code Execution Vulnerability

**According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?** Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

Microsoft Security Response Center
#sql#vulnerability#web#microsoft#rce#auth#SQL Server#Security Vulnerability
CVE-2022-29143: Microsoft SQL Server Remote Code Execution Vulnerability

**According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?** Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.

CVE-2022-23276: SQL Server for Linux Containers Elevation of Privilege Vulnerability

**If I'm running SQL Server 2019 on premise, am I vulnerable to this CVE?** This vulnerability only exists in the containerized version of SQL Server 2019 for Linux. If you are running that version, Microsoft recommends applying the update.