CVE-2025-49759SQL Injection in Microsoft SQL Server 2016 Service Pack 3

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGHNVD
EPSS
0.2%
top 62.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5microsoft/microsoft_sql_server_201714.0.014.0.3500.1+1
CVEListV5microsoft/microsoft_sql_server_201915.0.0.015.0.4440.1+1
CVEListV5microsoft/microsoft_sql_server_202216.0.0.016.0.4210.1+1
CVEListV5microsoft/microsoft_sql_server_2016_service_pack_313.0.013.0.6465.1

🔴Vulnerability Details

2
CVEList
Microsoft SQL Server Elevation of Privilege Vulnerability2025-08-12
GHSA
GHSA-hwf4-qmx5-35cv: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges2025-08-12

📋Vendor Advisories

1
Microsoft
Microsoft SQL Server Elevation of Privilege Vulnerability2025-08-12
CVE-2025-49759 — SQL Injection in Microsoft | cvebase