First published: Thu Nov 10 2016(Updated: )
Microsoft SQL Server 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7249 is classified as an Elevation of Privilege vulnerability.
To fix CVE-2016-7249, apply the latest security updates provided by Microsoft for SQL Server 2016.
Remote authenticated users of Microsoft SQL Server 2016 are affected by CVE-2016-7249.
CVE-2016-7249 allows remote authenticated users to gain elevated privileges on the affected system.
As of now, there are no specific public exploits documented for CVE-2016-7249.