Microsoft SQL Server Elevation of Privilege Vulnerabilities
Last Update Date:
13 Aug 2014 15:13
Release Date:
13 Aug 2014
4042
Views
RISK: Medium Risk
TYPE: Servers - Database Servers
- SQL Master Data Services XSS Vulnerability
An XSS vulnerability exists in SQL Master Data Services (MDS) that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take on the site on behalf of the targeted user. - Microsoft SQL Server Stack Overrun Vulnerability
A denial of service vulnerability exists in SQL Server. An attacker who successfully exploited this vulnerability could cause the server to stop responding until a manual reboot is initiated.
Impact
- Cross-Site Scripting
- Denial of Service
- Elevation of Privilege
- Information Disclosure
- Spoofing
System / Technologies affected
- SQL Server 2008
- SQL Server 2008 R2
- SQL Server 2012
- SQL Server 2014
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS14-044
Vulnerability Identifier
Source
Related Link
Share with