| Vulnerability Name: | CVE-2016-7253 (CCN-118345) | ||||||||||||
| Assigned: | 2016-11-08 | ||||||||||||
| Published: | 2016-11-08 | ||||||||||||
| Updated: | 2018-10-12 | ||||||||||||
| Summary: | The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Server Agent Elevation of Privilege Vulnerability." | ||||||||||||
| CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-7253 Source: CCN Type: Microsoft Security Bulletin MS16-136 Security Update for SQL Server (3199641) Source: BID Type: Third Party Advisory, VDB Entry 94056 Source: CCN Type: BID-94056 Microsoft SQL Server CVE-2016-7253 Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1037250 Source: MS Type: UNKNOWN MS16-136 Source: XF Type: UNKNOWN ms-sqlserver-cve20167253-priv-esc(118345) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||