This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account.
Affected Software | Affected Version | How to fix |
---|---|---|
MariaDB Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-16207 is considered high due to the potential for local privilege escalation.
To fix ZDI-CAN-16207, you should update your MariaDB installation to the latest version that addresses this vulnerability.
ZDI-CAN-16207 can be exploited by local attackers who have authentication access to the affected MariaDB installation.
ZDI-CAN-16207 affects specific versions of MariaDB Server, but the exact versions can be determined by checking the latest security advisories.
ZDI-CAN-16207 is classified as a privilege escalation vulnerability in MariaDB.