← All CVEs

CVE-2016-7253

high · 8.8

The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Server Agent Elevation of Privilege Vulnerability."

8.8
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2016-11-10
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftsql_server2012
microsoftsql_server2012
microsoftsql_server2014
microsoftsql_server2014

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-7253