CVE-2016-7254: High severity microsoft sql server vulnerability
Published Nov 10, 2016
·Updated
Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."
Affected Software
2 affected components
Microsoft SQL Server=2012-sp2
Microsoft SQL Server=2012-sp3
Event History
Nov 10, 2016
CVE Published
via MITRE·06:16 AM
Data Sourced
via MITRE·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7254?
CVE-2016-7254 has a severity rating of important, indicating it can allow elevation of privilege.
2
Who is affected by CVE-2016-7254?
CVE-2016-7254 affects Microsoft SQL Server 2012 SP2 and SP3 installations.
3
How do I fix CVE-2016-7254?
To resolve CVE-2016-7254, apply the latest security updates provided by Microsoft for SQL Server 2012 SP2 and SP3.
4
What type of vulnerability is CVE-2016-7254?
CVE-2016-7254 is classified as an elevation of privilege vulnerability in Microsoft SQL Server.
5
Can CVE-2016-7254 be exploited remotely?
Yes, CVE-2016-7254 allows remote authenticated users to exploit the vulnerability.