cbcvebase.
CVE-2018-8273
published 2018-08-15

CVE-2018-8273: A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server…

PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
29.21%
97.9th percentile
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

Affected

12 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sql_server
microsoftmicrosoft_sql_server
microsoftmicrosoft_sql_server
microsoftmicrosoft_sql_server
microsoftmicrosoft_sql_server
microsoftmicrosoft_sql_server
microsoftsql_server
microsoftsql_server
microsoftsql_server
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_1
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_2
msrcmicrosoft_sql_server_2017_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2018-8273 requires an attacker to submit a specially crafted SQL query to trigger the buffer overflow; monitor for anomalous or malformed SQL queries targeting SQL Server 2016/2017 instances, especially from external or low-privilege sources.
  • Exploitation can be chained via SQL injection vulnerabilities in web applications; correlate SQL Server execution anomalies with upstream web application traffic to identify injection-based attack chains.
  • Successful exploitation results in code execution under the SQL Server Database Engine service account; alert on unexpected child processes or privilege escalation originating from the SQL Server service account.
  • ·The vulnerability also affects SQL Server 2017 running on Linux and Linux Docker Containers; detection and patching scope must include non-Windows deployments.
  • ·Microsoft's exploit assessment rates exploitation as 'Less Likely' for both latest and older software releases, and no public exploit or in-the-wild exploitation was confirmed at time of disclosure.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.