PT-2025-32772 · Microsoft · Sql Server

Chris Thompson

+1

·

Published

2025-08-12

·

Updated

2026-01-20

·

CVE-2025-49758

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SQL Server (affected versions not specified)
Description The software contains an improper neutralization of special elements in SQL commands, leading to a potential SQL injection issue. This allows an authorized attacker to elevate privileges over a network. Additionally, an elevation-of-privilege issue can allow attackers to affect the system. The vulnerability is related to incorrect privilege assignment within the database management system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-10657
CVE-2025-49758

Affected Products

Sql Server