Lucene search

K
kasperskyKaspersky LabKLA12043
HistoryJan 12, 2021 - 12:00 a.m.

KLA12043 PE vulnerability in Microsoft SQL Server

2021-01-1200:00:00
Kaspersky Lab
threats.kaspersky.com
83

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.2%

An elevation of privilege vulnerability was found in Microsoft SQL Server. Malicious users can exploit this vulnerability to gain privileges.

Original advisories

CVE-2021-1636

Exploitation

Public exploits exist for this vulnerability.

Related products

Microsoft-SQL-Server

CVE list

CVE-2021-1636 critical

KB list

4583461

4583456

4583457

4583459

4583462

4583465

4583458

4583460

4583463

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)Microsoft SQL Server 2017 for x64-based Systems (CU 22)Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)Microsoft SQL Server 2017 for x64-based Systems (GDR)Microsoft SQL Server 2019 for x64-based Systems (GDR)Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU 4)Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)Microsoft SQL Server 2016 Service Pack 2 for x64-based Systems (CU 15)Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)Microsoft SQL Server 2019 for x64-based Systems (CU 8)Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU 4)

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.2%