CVE-2025-49758: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49758?
CVE-2025-49758 has a high severity rating due to the potential for privilege escalation in Microsoft SQL Server.
How do I fix CVE-2025-49758?
To fix CVE-2025-49758, apply the latest cumulative updates provided by Microsoft for the affected SQL Server versions.
Which versions of SQL Server are affected by CVE-2025-49758?
CVE-2025-49758 affects Microsoft SQL Server 2016, 2017, 2019, and 2022 in specific cumulative update versions.
What kind of vulnerability is CVE-2025-49758?
CVE-2025-49758 is an elevation of privilege vulnerability caused by improper neutralization of special elements in SQL commands.
Can CVE-2025-49758 be exploited remotely?
Yes, CVE-2025-49758 can be exploited by an authorized attacker over a network, increasing the risk of privilege escalation.