CVE-2016-7253
high-risk
Published 2016-11-10
The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Server Agent Elevation of Privilege Vulnerability."
Do I need to act?
!
18.2% chance of exploitation in next 30 days
EPSS score — higher than 82% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (4)
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/94056
Third Party Advisory
http://www.securityfocus.com/bid/94056
53
/ 100
high-risk
Severity
30/34 · Critical
Exploitability
13/34 · Low
Exposure
10/34 · Low