CVE-2016-7252: Infoleak
Published Nov 10, 2016
·Updated
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
Affected Software
1 affected component
Microsoft SQL Server=2016
Event History
Nov 10, 2016
CVE Published
via MITRE·06:16 AM
Data Sourced
via MITRE·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7252?
CVE-2016-7252 has been assigned a high severity rating due to its potential to allow privilege escalation.
2
How do I fix CVE-2016-7252?
To fix CVE-2016-7252, apply the latest security updates provided by Microsoft for SQL Server 2016.
3
Who is affected by CVE-2016-7252?
CVE-2016-7252 affects remote authenticated users of Microsoft SQL Server 2016.
4
What type of vulnerability is CVE-2016-7252?
CVE-2016-7252 is categorized as an information disclosure vulnerability.
5
Can CVE-2016-7252 be exploited remotely?
Yes, CVE-2016-7252 can be exploited remotely by authenticated users.