CVE-2016-7253
high · 8.8The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Server Agent Elevation of Privilege Vulnerability."
8.8
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2016-11-10
Published
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | sql_server | 2012 |
| microsoft | sql_server | 2012 |
| microsoft | sql_server | 2014 |
| microsoft | sql_server | 2014 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/94056
- http://www.securitytracker.com/id/1037250
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-136
- http://www.securityfocus.com/bid/94056
- http://www.securitytracker.com/id/1037250
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-136
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-7253