CVE-2016-7250: High severity microsoft sql server vulnerability
Published Nov 10, 2016
·Updated
Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."
Affected Software
3 affected components
Microsoft SQL Server=2014-sp1
Microsoft SQL Server=2014-sp2
Microsoft SQL Server=2016
Event History
Nov 10, 2016
CVE Published
via MITRE·06:16 AM
Data Sourced
via MITRE·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7250?
CVE-2016-7250 is classified as an elevation of privilege vulnerability.
2
How do I fix CVE-2016-7250?
To fix CVE-2016-7250, apply the latest security updates provided by Microsoft for SQL Server.
3
Which versions of SQL Server are affected by CVE-2016-7250?
CVE-2016-7250 affects Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016.
4
Can unprivileged users exploit CVE-2016-7250?
Yes, CVE-2016-7250 allows remote authenticated users to potentially gain higher privileges.
5
What is the nature of the vulnerability described in CVE-2016-7250?
CVE-2016-7250 arises from improper pointer casting that can lead to privilege escalation.