CVE-2025-55227: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55227?
CVE-2025-55227 is classified as a high-severity elevation of privilege vulnerability in Microsoft SQL Server.
How do I fix CVE-2025-55227?
To resolve CVE-2025-55227, apply the appropriate security patches for your version of Microsoft SQL Server.
Which versions of SQL Server are affected by CVE-2025-55227?
CVE-2025-55227 affects multiple versions of Microsoft SQL Server, including 2016, 2017, 2019, and 2022.
What type of vulnerability is CVE-2025-55227?
CVE-2025-55227 is a command injection vulnerability that allows an attacker to elevate privileges over a network.
Can an authorized attacker exploit CVE-2025-55227?
Yes, an authorized attacker can exploit CVE-2025-55227 to gain elevated privileges on the affected SQL Server systems.