cbcvebase.
CVE-2021-1636
published 2021-01-12

CVE-2021-1636: Microsoft SQL Elevation of Privilege Vulnerability

PriorityP279high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.15%
92.7th percentile
Microsoft SQL Elevation of Privilege Vulnerability

Affected

22 ranges
VendorProductVersion rangeFixed in
googlechrome_chrome
microsoftmicrosoft_sql_server_2012_for_x64-based_systems_service_pack_4>= 11.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2012_service_pack_4>= 11.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2014_service_pack_3>= 12.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_2>= 13.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2016_service_pack_2>= 13.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2017>= 14.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2019>= 15.0.0 < publicationpublication
microsoftmicrosoft_sql_server_2019>= 16.0.0 < publicationpublication
microsoftsql_server
microsoftsql_server
microsoftsql_server
microsoftsql_server
microsoftsql_server
msrcmicrosoft_sql_server_2012_for_32-bit_systems_service_pack_4
msrcmicrosoft_sql_server_2012_for_x64-based_systems_service_pack_4
msrcmicrosoft_sql_server_2014_service_pack_3_for_32-bit_systems
msrcmicrosoft_sql_server_2014_service_pack_3_for_x64-based_systems
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_2
msrcmicrosoft_sql_server_2016_service_pack_2_for_x64-based_systems
msrcmicrosoft_sql_server_2017_for_x64-based_systems
msrcmicrosoft_sql_server_2019_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires an authenticated attacker sending data over a network to an affected SQL Server instance that is configured to run an Extended Event session — monitor for unexpected or anomalous Extended Event session activity on SQL Server
  • ·The attack surface is only present when SQL Server is configured to run an Extended Event session; disabling or restricting Extended Event sessions reduces exposure
  • ·Affected SQL Server versions span 2012 through 2019 across RTM, GDR, and CU update paths; ensure the correct patch track (GDR vs CU) is applied and note that switching from GDR to CU is a one-way operation

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.