PT-2022-3053 · Microsoft+1 · Sql Express 2019+1

Published

2022-06-17

·

Updated

2023-08-08

·

CVE-2022-34006

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Titan FTP Server NextGen versions prior to 1.2.1050
Description The issue is related to errors during the installation of Microsoft SQL Express 2019, which allows an attacker to execute arbitrary commands with elevated privileges. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTINUsers as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITYSYSTEM.
Recommendations For versions prior to 1.2.1050, as a temporary workaround, consider restricting access to the SQL instance running as SYSTEM to minimize the risk of exploitation. To fully resolve the issue, update to version 1.2.1050 or later, which corrects this vulnerability in new installations. However, note that the 1.2.1050 release does not correct this vulnerability in upgrade installations.

Fix

Improper Privilege Management

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-03722
CVE-2022-34006

Affected Products

Sql Express 2019
Titan Ftp Server Nextgen