CVE-2025-59499: Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59499?
CVE-2025-59499 has been rated as a critical severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-59499?
To fix CVE-2025-59499, apply the latest security updates and patches provided by Microsoft for affected SQL Server versions.
Which versions of SQL Server are affected by CVE-2025-59499?
CVE-2025-59499 affects multiple versions of Microsoft SQL Server including SQL Server 2016, 2017, 2019, and 2022.
Can CVE-2025-59499 be exploited remotely?
Yes, CVE-2025-59499 can be exploited over a network by an authorized attacker.
What type of vulnerability is CVE-2025-59499?
CVE-2025-59499 is classified as an SQL injection vulnerability that allows for elevation of privilege.