cbcvebase.
CVE-2025-24999
published 2025-08-12

CVE-2025-24999: Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.63%
73.5th percentile
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected

21 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sql_server_2016_service_pack_3>= 13.0.0 < 13.0.6465.113.0.6465.1
microsoftmicrosoft_sql_server_2016_service_pack_3_azure_connect_feature_pack>= 13.0.0 < 13.0.7060.113.0.7060.1
microsoftmicrosoft_sql_server_2017>= 14.0.0 < 14.0.3500.114.0.3500.1
microsoftmicrosoft_sql_server_2017>= 14.0.0 < 14.0.2080.114.0.2080.1
microsoftmicrosoft_sql_server_2019>= 15.0.0 < 15.0.2140.115.0.2140.1
microsoftmicrosoft_sql_server_2019>= 15.0.0.0 < 15.0.4440.115.0.4440.1
microsoftmicrosoft_sql_server_2022>= 16.0.0 < 16.0.1145.116.0.1145.1
microsoftmicrosoft_sql_server_2022>= 16.0.0.0 < 16.0.4210.116.0.4210.1
microsoftsql_server_2016>= 13.0.6300.2 < 13.0.6465.113.0.6465.1
microsoftsql_server_2016>= 13.0.7000.253 < 13.0.7060.113.0.7060.1
microsoftsql_server_2017>= 14.0.1000.169 < 14.0.2080.114.0.2080.1
microsoftsql_server_2017>= 14.0.3006.16 < 14.0.3500.114.0.3500.1
microsoftsql_server_2019>= 15.0.2000.5 < 15.0.2140.115.0.2140.1
microsoftsql_server_2019>= 15.0.4003.23 < 15.0.4440.115.0.4440.1
microsoftsql_server_2022>= 16.0.1000.6 < 16.0.1145.116.0.1145.1
microsoftsql_server_2022>= 16.0.4003.1 < 16.0.4210.116.0.4210.1
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3_azure_connect_fea
msrcmicrosoft_sql_server_2017_for_x64-based_systems
msrcmicrosoft_sql_server_2019_for_x64-based_systems
msrcmicrosoft_sql_server_2022_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

  • An authenticated attacker with explicit permissions exploits improper access control in SQL Server over the network to elevate privileges to sysadmin. Monitor for unexpected sysadmin role assignments originating from low-privileged authenticated SQL logins.
  • Monitor for privilege escalation to sysadmin role in SQL Server audit logs, especially from accounts that should not hold sysadmin rights.
  • The attack vector is network-based; monitor for lateral movement or privilege escalation attempts against SQL Server instances exposed on the network.
  • ·Vulnerability affects SQL Server 2016 SP3, 2017, 2019, and 2022 across both RTM+GDR and CU update paths. Patched versions are: SQL 2022 CU20+GDR (16.0.4210.1), SQL 2022 RTM+GDR (16.0.1145.1), SQL 2019 CU32+GDR (15.0.4440.1), SQL 2019 RTM+GDR (15.0.2140.1), SQL 2017 CU31+GDR (14.0.3500.1), SQL 2017 RTM+GDR (14.0.2080.1), SQL 2016 Azure Connect Feature Pack (13.0.7060.1), SQL 2016 SP3 RTM+GDR (13.0.6465.1). Unpatched instances within the listed version ranges remain vulnerable.
  • ·Exploit status is currently 'Exploitation Less Likely' with no public exploit or in-the-wild exploitation confirmed at time of advisory publication.
  • ·Once a SQL Server CU update is applied, there is no way to revert to the GDR update path. Choose the correct update track (GDR vs CU) based on the current installation's update history before patching.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.