Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | sql server management studio | 22.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| microsoft | microsoft windows | cert_advisory | 90% |
| microsoft | microsoft windows server 2012 r2 | cert_advisory | 90% |
Loading…