Lucene search

K
kasperskyKaspersky LabKLA11310
HistoryAug 14, 2018 - 12:00 a.m.

KLA11310 ACE vulnerability in Microsoft SQL Server

2018-08-1400:00:00
Kaspersky Lab
threats.kaspersky.com
545

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10 High

AI Score

Confidence

High

0.086 Low

EPSS

Percentile

94.5%

A buffer overflow vulnerability was found in Microsoft SQL Server. Malicious users can exploit this vulnerability via specially crafted query to execute arbitrary code.

Original advisories

CVE-2018-8273

Related products

Microsoft-SQL-Server

CVE list

CVE-2018-8273 critical

KB list

4293808

4293805

4293802

4293803

4458621

4458842

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 1Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (CU)Microsoft SQL Server 2016 for x64-based Systems Service Pack 2Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU)Microsoft SQL Server 2017 for x64-based SystemsMicrosoft SQL Server 2017 for x64-based Systems (CU)

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10 High

AI Score

Confidence

High

0.086 Low

EPSS

Percentile

94.5%