CVE-2025-24999
published 2025-08-12CVE-2025-24999: Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.63%
73.5th percentile
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sql_server_2016_service_pack_3 | >= 13.0.0 < 13.0.6465.1 | 13.0.6465.1 |
| microsoft | microsoft_sql_server_2016_service_pack_3_azure_connect_feature_pack | >= 13.0.0 < 13.0.7060.1 | 13.0.7060.1 |
| microsoft | microsoft_sql_server_2017 | >= 14.0.0 < 14.0.3500.1 | 14.0.3500.1 |
| microsoft | microsoft_sql_server_2017 | >= 14.0.0 < 14.0.2080.1 | 14.0.2080.1 |
| microsoft | microsoft_sql_server_2019 | >= 15.0.0 < 15.0.2140.1 | 15.0.2140.1 |
| microsoft | microsoft_sql_server_2019 | >= 15.0.0.0 < 15.0.4440.1 | 15.0.4440.1 |
| microsoft | microsoft_sql_server_2022 | >= 16.0.0 < 16.0.1145.1 | 16.0.1145.1 |
| microsoft | microsoft_sql_server_2022 | >= 16.0.0.0 < 16.0.4210.1 | 16.0.4210.1 |
| microsoft | sql_server_2016 | >= 13.0.6300.2 < 13.0.6465.1 | 13.0.6465.1 |
| microsoft | sql_server_2016 | >= 13.0.7000.253 < 13.0.7060.1 | 13.0.7060.1 |
| microsoft | sql_server_2017 | >= 14.0.1000.169 < 14.0.2080.1 | 14.0.2080.1 |
| microsoft | sql_server_2017 | >= 14.0.3006.16 < 14.0.3500.1 | 14.0.3500.1 |
| microsoft | sql_server_2019 | >= 15.0.2000.5 < 15.0.2140.1 | 15.0.2140.1 |
| microsoft | sql_server_2019 | >= 15.0.4003.23 < 15.0.4440.1 | 15.0.4440.1 |
| microsoft | sql_server_2022 | >= 16.0.1000.6 < 16.0.1145.1 | 16.0.1145.1 |
| microsoft | sql_server_2022 | >= 16.0.4003.1 < 16.0.4210.1 | 16.0.4210.1 |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_3 | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_3_azure_connect_fea | — | — |
| msrc | microsoft_sql_server_2017_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2019_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2022_for_x64-based_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An authenticated attacker with explicit permissions exploits improper access control in SQL Server over the network to elevate privileges to sysadmin. Monitor for unexpected sysadmin role assignments originating from low-privileged authenticated SQL logins. ↗
- →Monitor for privilege escalation to sysadmin role in SQL Server audit logs, especially from accounts that should not hold sysadmin rights. ↗
- →The attack vector is network-based; monitor for lateral movement or privilege escalation attempts against SQL Server instances exposed on the network. ↗
- ·Vulnerability affects SQL Server 2016 SP3, 2017, 2019, and 2022 across both RTM+GDR and CU update paths. Patched versions are: SQL 2022 CU20+GDR (16.0.4210.1), SQL 2022 RTM+GDR (16.0.1145.1), SQL 2019 CU32+GDR (15.0.4440.1), SQL 2019 RTM+GDR (15.0.2140.1), SQL 2017 CU31+GDR (14.0.3500.1), SQL 2017 RTM+GDR (14.0.2080.1), SQL 2016 Azure Connect Feature Pack (13.0.7060.1), SQL 2016 SP3 RTM+GDR (13.0.6465.1). Unpatched instances within the listed version ranges remain vulnerable. ↗
- ·Exploit status is currently 'Exploitation Less Likely' with no public exploit or in-the-wild exploitation confirmed at time of advisory publication. ↗
- ·Once a SQL Server CU update is applied, there is no way to revert to the GDR update path. Choose the correct update track (GDR vs CU) based on the current installation's update history before patching. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g9qp-9hg6-hmp7: Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network
ghsa_unreviewed·2025-08-12
CVE-2025-24999 [HIGH] CWE-284 GHSA-g9qp-9hg6-hmp7: Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Microsoft
Microsoft SQL Server Elevation of Privilege Vulnerability
vendor_msrc·2025-08-12·CVSS 8.8
CVE-2025-24999 [HIGH] CWE-284 Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
Description: Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
FAQ: How could an attacker exploit this vulnerability?
An authenticated attacker with explicit permissions could exploit the vulnerability by logging in to the SQL server and could then elevate their privileges to sysadmin.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain sysadmin privileges.
FAQ: I am running SQL Server on my system. What action do I need to take?
Update your relevant version of SQL Server. Any applicable driver fixes are included in those updates.
There are GDR and/or CU (Cumul
No detection rules found.
No public exploits indexed.
2025-08-12
Published