CVE-2016-7252
published 2016-11-10CVE-2016-7252: Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis…
PriorityP343medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
17.57%
96.8th percentile
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sql_server | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5r28-jxxq-f3c4: Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL
ghsa_unreviewed·2022-05-14
CVE-2016-7252 [MEDIUM] CWE-200 GHSA-5r28-jxxq-f3c4: Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
Microsoft
Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
vendor_msrc·2016-11-08·CVSS 6.5
CVE-2016-7252 [MEDIUM] Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces permissions. An attacker could exploit the vulnerability if the attacker's credentials allow access to an affected SQL server database.
An attacker who successfully exploited the vulnerability could gain additional database and file information.
The security update addresses the vulnerability by correcting how SQL Server Analysis Services enforces permissions.
FAQ: There are GDR and/or CU (Cumulative Update) updates offered for my version of SQL Server. How do I know which update to use?
First, determine your SQL Server version number. For more information on determining your SQL Serve
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94050http://www.securitytracker.com/id/1037250https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-136http://www.securityfocus.com/bid/94050http://www.securitytracker.com/id/1037250https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-136
2016-11-10
Published