VDB
GCVE-110-NCSC-2025-247
GCVE-110-NCSC-2025-247
Advisory PublishedCVSS 8.8/10
Microsoft heeft kwetsbaarheden verholpen in SQL Server.
Weaknesses (CWE)
CWE-284Improper Access ControlCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-269Improper Privilege Management
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/>=16.0.4003.1 cu19|<=16.0.4205.1 cu19 | — | — |
| Microsoft | vers:unknown/15.0.0|<15.0.2140.1 | — | — |
| Microsoft | vers:microsoft/15.0.4440.1 cu32 on x86 64 | — | — |
| Microsoft | vers:unknown/>=13.0.7000.253 azure connect feature pack|<=13.0.7055.9 azure connect feature pack | — | — |
| Microsoft | vers:unknown/>=13.0.6300.2 sp3|<=13.0.6460.7 sp3 | — | — |
| Microsoft | vers:unknown/14.0.0|<14.0.2080.1 | — | — |
| Microsoft | vers:microsoft/unknown | — | — |
| Microsoft | vers:unknown/13.0.0|<13.0.7060.1 | — | — |
| Microsoft | vers:unknown/unknown | — | — |
| Microsoft | vers:unknown/14.0.0|<14.0.3500.1 | — | — |
| Microsoft | vers:unknown/13.0.0|<13.0.6465.1 | — | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.