CVE-2025-47954: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47954?
CVE-2025-47954 has a significant severity level as it allows an authorized attacker to elevate privileges through SQL injection in Microsoft SQL Server.
How do I fix CVE-2025-47954?
To fix CVE-2025-47954, apply the patches available for the affected versions of SQL Server as provided by Microsoft.
What versions of SQL Server are affected by CVE-2025-47954?
CVE-2025-47954 affects Microsoft SQL Server 2022 and its cumulative updates.
What kind of attack does CVE-2025-47954 enable?
CVE-2025-47954 enables an SQL injection attack that can result in privilege escalation over a network.
Who is vulnerable to CVE-2025-47954?
Organizations using vulnerable versions of Microsoft SQL Server 2022 are at risk of exploitation from CVE-2025-47954.