CVE-2025-49759: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49759?
CVE-2025-49759 is rated as a high-severity vulnerability due to its potential for privilege escalation.
What types of attacks can CVE-2025-49759 facilitate?
CVE-2025-49759 can allow an authorized attacker to perform SQL injection attacks, leading to unauthorized privilege elevation.
How do I fix CVE-2025-49759?
To mitigate CVE-2025-49759, it is recommended to apply the latest security patches provided by Microsoft for affected SQL Server versions.
Which versions of SQL Server are affected by CVE-2025-49759?
CVE-2025-49759 affects Microsoft SQL Server 2016, 2017, 2019, and 2022 across various cumulative updates and service packs.
Is CVE-2025-49759 being actively exploited?
As of now, there are no public reports of active exploitation for CVE-2025-49759, but it is important to patch as a precaution.