CVE-2025-49758

Severity
8.8HIGH
EPSS
0.1%
top 65.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5microsoft/microsoft_sql_server_2017_(gdr)14.0.014.0.2080.1
CVEListV5microsoft/microsoft_sql_server_2019_(gdr)15.0.015.0.2140.1
CVEListV5microsoft/microsoft_sql_server_2022_(gdr)16.0.016.0.1145.1
CVEListV5microsoft/microsoft_sql_server_2017_(cu_31)14.0.014.0.3500.1
CVEListV5microsoft/microsoft_sql_server_2019_(cu_32)15.0.0.015.0.4440.1

🔴Vulnerability Details

2
GHSA
GHSA-4r6w-pg4g-qvvh: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges2025-08-12
CVEList
Microsoft SQL Server Elevation of Privilege Vulnerability2025-08-12

📋Vendor Advisories

1
Microsoft
Microsoft SQL Server Elevation of Privilege Vulnerability2025-08-12
CVE-2025-49758 (HIGH CVSS 8.8) | Improper neutralization of special | cvebase.io