CVE-2017-8516
published 2017-08-08CVE-2017-8516: Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
8.04%
94.1th percentile
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability".
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft_corporation | sql_server | — | — |
| msrc | microsoft_sql_server_2012_for_32-bit_systems_service_pack_3 | — | — |
| msrc | microsoft_sql_server_2012_for_x64-based_systems_service_pack_3 | — | — |
| msrc | microsoft_sql_server_2014_service_pack_1_for_32-bit_systems | — | — |
| msrc | microsoft_sql_server_2014_service_pack_1_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2014_service_pack_2_for_32-bit_systems | — | — |
| msrc | microsoft_sql_server_2014_service_pack_2_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_1 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
vendor_msrc·2017-08-08·CVSS 7.5
CVE-2017-8516 [HIGH] Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
Microsoft SQL Server Analysis Services Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces permissions. An attacker could exploit the vulnerability if the attacker's credentials allow access to an affected SQL server database.
An attacker who successfully exploited the vulnerability could gain additional database and file information.
The security update addresses the vulnerability by correcting how SQL Server Analysis Services enforces permissions.
FAQ: There are GDR and/or CU (Cumulative Update) updates offered for my version of SQL Server. How do I know which update to use?
First, determine your SQL Server version number. For more information on determining your SQL Serv
GHSA
GHSA-qgr4-h86c-w3g3: Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information di
ghsa_unreviewed·2022-05-17
CVE-2017-8516 [HIGH] CWE-200 GHSA-qgr4-h86c-w3g3: Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information di
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information Disclosure Vulnerability".
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - August 2017
blogs_talos·2017-08-08·CVSS 7.8
[HIGH] Microsoft Patch Tuesday - August 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 48 new vulnerabilities with 25 of them rated critical, 21 rated important, and 2 rated moderate. These vulnerabilities impact Edge, Hyper-V, Internet Explorer, Remote Desktop Protocol, Sharepoint, SQL Server, the Windows Subsystem for Linux, and more. In addition, Microsoft is also releasing an update for Adobe Flash Player embedded in Edge and Internet Explorer.
## Vulnerabilities Rated Critical The following vulnerabilities are rated "critical" by Microsoft:
- CVE-2017-8653 - Microsoft Browser Memory Corruption Vulnerability
- CVE-2017-8669 - Microsoft Browser Memory Corruption Vulnerability
- CVE-2017-866
Talos
Microsoft Patch Tuesday - August 2017
blogs_talos·2017-08-08·CVSS 7.8
[HIGH] Microsoft Patch Tuesday - August 2017
## Microsoft Patch Tuesday - August 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 48 new vulnerabilities with 25 of them rated critical, 21 rated important, and 2 rated moderate. These vulnerabilities impact Edge, Hyper-V, Internet Explorer, Remote Desktop Protocol, Sharepoint, SQL Server, the Windows Subsystem for Linux, and more. In addition, Microsoft is also releasing an update for Adobe Flash Player embedded in Edge and Internet Explorer.
## Vulnerabilities Rated Critical The following vulnerabilities are rated "critical" by Microsoft:
CVE-2017-8653 - Microsoft Browser Memory Corruption Vulnerability
CVE-2017-8669 - Microsoft Browser Memory
http://www.securityfocus.com/bid/100041http://www.securitytracker.com/id/1039110https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8516http://www.securityfocus.com/bid/100041http://www.securitytracker.com/id/1039110https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8516
2017-08-08
Published