CVE-2016-7250

Description

Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka SQL RDBMS Engine Elevation of Privilege Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
16.567

Associated Vulnerability

VulnerabilityOS Platform
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 1 GDR (KB3194720) x86 based systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 1 GDR (KB3194720) x64 bases systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 1 CU (KB3194722) x86 based systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 1 CU (KB3194722) x64 bases systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 2 GDR (KB3194714)Windows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 2 GDR (KB3194714) x64 bases systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 2 CU (KB3194718) x86 based systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2014 Service Pack 2 CU (KB3194718) x64 bases systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2016 RTM GDR (KB3194716) x86 based systemsWindows
SQL RDBMS Engine Elevation of Privilege Vulnerability for SQL Server 2016 RTM GDR (KB3194716) x64 bases systemsWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21809Security Update for SQL Server 2014 Service Pack 1 GDR (KB3194720) 32 bit
PATCH-21810Security Update for SQL Server 2014 Service Pack 1 GDR (KB3194720) 64 bit
PATCH-21811Security Update for SQL Server 2014 Service Pack 1 CU (KB3194722) 32 bit
PATCH-21812Security Update for SQL Server 2014 Service Pack 1 CU (KB3194722) 64 bit
PATCH-21814Security Update for SQL Server 2014 Service Pack 2 GDR (KB3194714) 64 bit
PATCH-21815Security Update for SQL Server 2014 Service Pack 2 CU (KB3194718) 32 bit
PATCH-21816Security Update for SQL Server 2014 Service Pack 2 CU (KB3194718) 64 bit
PATCH-21817Security Update for SQL Server 2016 RTM GDR (KB3194716) 32 bit
PATCH-21818Security Update for SQL Server 2016 RTM GDR (KB3194716) 64 bit

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234