CVE-2018-8273
published 2018-08-15CVE-2018-8273: A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
29.21%
97.9th percentile
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_1 | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_2 | — | — |
| msrc | microsoft_sql_server_2017_for_x64-based_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2018-8273 requires an attacker to submit a specially crafted SQL query to trigger the buffer overflow; monitor for anomalous or malformed SQL queries targeting SQL Server 2016/2017 instances, especially from external or low-privilege sources. ↗
- →Exploitation can be chained via SQL injection vulnerabilities in web applications; correlate SQL Server execution anomalies with upstream web application traffic to identify injection-based attack chains. ↗
- →Successful exploitation results in code execution under the SQL Server Database Engine service account; alert on unexpected child processes or privilege escalation originating from the SQL Server service account. ↗
- ·The vulnerability also affects SQL Server 2017 running on Linux and Linux Docker Containers; detection and patching scope must include non-Windows deployments. ↗
- ·Microsoft's exploit assessment rates exploitation as 'Less Likely' for both latest and older software releases, and no public exploit or in-the-wild exploitation was confirmed at time of disclosure. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xq9g-9hx4-3c38: A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Se
ghsa_unreviewed·2022-05-13
CVE-2018-8273 [CRITICAL] CWE-787 GHSA-xq9g-9hx4-3c38: A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Se
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.
Microsoft
Microsoft SQL Server Remote Code Execution Vulnerability
vendor_msrc·2018-08-14·CVSS 9.8
CVE-2018-8273 [CRITICAL] Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Description: A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system. An attacker who successfully exploited this vulnerability could execute code in the context of the SQL Server Database Engine service account.
To exploit the vulnerability, an attacker would need to submit a specially crafted query to an affected SQL server.
The security update addresses the vulnerability by modifying how the Microsoft SQL Server Database Engine handles objects in memory.
FAQ: There are GDR and/or CU (Cumulative Update) updates offered for my version of SQL Server. How do I know which update to use?
First, determine your SQL Server version number. For more information on det
No detection rules found.
No public exploits indexed.
Talos
Microsoft Tuesday August 2018
blogs_talos·2018-08-14·CVSS 9.8
[CRITICAL] Microsoft Tuesday August 2018
## Microsoft Tuesday August 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 62 new vulnerabilities, 20 of which are rated “critical,” 38 that are rated “important,” one that is rated moderate and one that is rated as low severity. These vulnerabilities impact Windows Operating System, Edge and Internet Explorer, along with several other products.
In addition to the 60 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180020 which addresses the vulnerabilities described in the Adobe Flash Security Bulletin APSB18-25.
## Critical Vulnerabilities
This month, Microsoft is addressing 20 vulnerabilities that a
Qualys
August 2018 Patch Tuesday – 63 Vulns, L1TF (Foreshadow), Exchange, SQL, Active Attacks on IE flaw
blogs_qualys·2018-08-14·CVSS 9.8
CVE-2018-8373 [CRITICAL] August 2018 Patch Tuesday – 63 Vulns, L1TF (Foreshadow), Exchange, SQL, Active Attacks on IE flaw
In this month’s Patch Tuesday release there are 63 vulnerabilities patched with 20 Criticals. Out of the criticals, over half are browser-related, with the rest including Windows, SQL, and Exchange. Active exploits have been detected against CVE-2018-8373, one of the scripting engine vulnerabilities.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. Microsoft has disclosed that CVE-2018-8373 has active exploits against Internet Explorer, making these patches a high priority. The PDF viewer, Windows Font Library, and GDI+ also have patches available that require a user to interact with a malicious site or file.
## LNK Remote Code Execution
A vu
Qualys
Patch Tuesday August 2018: Active IE Attacks | Qualys
blogs_qualys·2018-08-14·CVSS 9.8
CVE-2018-8373 [CRITICAL] Patch Tuesday August 2018: Active IE Attacks | Qualys
In this month’s Patch Tuesday release there are 63 vulnerabilities patched with 20 Criticals. Out of the criticals, over half are browser-related, with the rest including Windows, SQL, and Exchange. Active exploits have been detected against CVE-2018-8373, one of the scripting engine vulnerabilities.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. Microsoft has disclosed that CVE-2018-8373 has active exploits against Internet Explorer, making these patches a high priority. The PDF viewer, Windows Font Library, and GDI+ also have patches available that require a user to interact with a malicious site or file.
### LNK Remote Code Execution
A
Talos
Microsoft Tuesday August 2018
blogs_talos·2018-08-14·CVSS 9.8
[CRITICAL] Microsoft Tuesday August 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 62 new vulnerabilities, 20 of which are rated “critical,” 38 that are rated “important,” one that is rated moderate and one that is rated as low severity. These vulnerabilities impact Windows Operating System, Edge and Internet Explorer, along with several other products.
In addition to the 60 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180020 which addresses the vulnerabilities described in the Adobe Flash Security Bulletin APSB18-25.
### Critical Vulnerabilities
This month, Microsoft is addressing 20 vulnerabilities that are rated "critical." Talos believ
http://www.securityfocus.com/bid/104967http://www.securitytracker.com/id/1041467https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8273http://www.securityfocus.com/bid/104967http://www.securitytracker.com/id/1041467https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8273
2018-08-15
Published