CVE-2025-59499

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 71.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11

Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages9 packages

CVEListV5microsoft/microsoft_sql_server_2017_(gdr)14.0.014.0.2095.1
CVEListV5microsoft/microsoft_sql_server_2019_(gdr)15.0.015.0.2155.2
CVEListV5microsoft/microsoft_sql_server_2022_(gdr)16.0.016.0.1160.1
CVEListV5microsoft/microsoft_sql_server_2017_(cu_31)14.0.014.0.3515.1
CVEListV5microsoft/microsoft_sql_server_2019_(cu_32)15.0.0.015.0.4455.2

🔴Vulnerability Details

2
CVEList
Microsoft SQL Server Elevation of Privilege Vulnerability2025-11-11
GHSA
GHSA-pm2c-qc4c-h96f: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges2025-11-11

📋Vendor Advisories

1
Microsoft
Microsoft SQL Server Elevation of Privilege Vulnerability2025-11-11
CVE-2025-59499 (HIGH CVSS 8.8) | Improper neutralization of special | cvebase.io