VDB

GCVE-110-NCSC-2025-247

GCVE-110-NCSC-2025-247
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 13, 2025
Microsoft heeft kwetsbaarheden verholpen in SQL Server.

Weaknesses (CWE)

CWE-284Improper Access ControlCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-269Improper Privilege Management

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/>=16.0.4003.1 cu19|<=16.0.4205.1 cu19
Microsoftvers:unknown/15.0.0|<15.0.2140.1
Microsoftvers:microsoft/15.0.4440.1 cu32 on x86 64
Microsoftvers:unknown/>=13.0.7000.253 azure connect feature pack|<=13.0.7055.9 azure connect feature pack
Microsoftvers:unknown/>=13.0.6300.2 sp3|<=13.0.6460.7 sp3
Microsoftvers:unknown/14.0.0|<14.0.2080.1
Microsoftvers:microsoft/unknown
Microsoftvers:unknown/13.0.0|<13.0.7060.1
Microsoftvers:unknown/unknown
Microsoftvers:unknown/14.0.0|<14.0.3500.1
Microsoftvers:unknown/13.0.0|<13.0.6465.1

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›