Microsoft SQL Server 2014 / 2016 /...

- AV AC AU C I A
发布: 2023-03-16
修订: 2024-10-05

Microsoft SQL Server 2014, 2016, 2017, 2019, and 2022 appears to ignore audit rules for sys.sysxlgns allowing an attacker with administrative permissions to extract password hashes under the radar. Microsoft told the researcher they are not willing to fix it but acknowledge it as a security problem.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息