Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
GHSA-8mmr-rphh-45c7: Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges↗2025-09-09
▶
CVEList
Microsoft SQL Server Elevation of Privilege Vulnerability↗2025-09-09
▶
📋Vendor Advisories
1
Microsoft
Microsoft SQL Server Elevation of Privilege Vulnerability↗2025-09-09
▶
CVE-2025-55227 (HIGH CVSS 8.8) | Improper neutralization of special | cvebase.io