SQLServerUpdates.com
  • Home – Most Recent Updates
    • SQL Server 2022 Updates
    • SQL Server 2019 Updates
    • SQL Server 2017 Updates
    • SQL Server 2016 Updates
    • SQL Server 2014 Updates
    • SQL Server 2012 Updates
    • SQL Server 2008 R2 Updates
    • SQL Server 2008 Updates
  • Download SQL Server
  • Subscribe to Updates
  • Contact Us
    • Frequently Asked Questions

New Security Updates to Fix SQL Injection Vulnerabilities

4 months ago
Brent Ozar
SQL Server 2016, SQL Server 2017, SQL Server 2019, SQL Server 2022, Updates
No Comments

No, not vulnerabilities in your code, but in Microsoft’s. Microsoft announced a round of GDRs yesterday that have an interesting set of bug fixes:

  • Fixes a SQL injection vulnerability in a system stored procedure.
  • Prevents logins with the ALTER ANY LOGIN permission from resetting the passwords of logins that have ALTER ANY LOGIN or IMPERSONATE ANY LOGIN permissions to avoid elevation of privilege.
  • Prevents elevation of privilege by running SQL Agent job steps for built-in jobs with reduced permissions.
  • Fixes a vulnerability that lets users who have access to certain stored procedures perform SQL injection and run arbitrary code by using elevated privileges.

No further details are available about the bugs in question, and I don’t blame Microsoft for not publishing it, either. Publishing details on any of these would allow The Bad Guys™ to cause Bad Things™ to the unpatched servers out there. Rather than being curious, get to patchin’ – all of the relevant pages have been updated on SQLServerUpdates.com with the new builds.

Brent Ozarhttps://sqlserverupdates.com
I make Microsoft SQL Server faster and more reliable. I love teaching, travel, and laughing.
Previous Post
A Bunch of Security Updates for 2016-2022 Just Dropped.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.

Subscribe

Want to get an email when Microsoft publishes a new SP or CU for SQL Server? Subscribe here.

Recent Updates

  • New Security Updates to Fix SQL Injection Vulnerabilities August 13, 2025
  • A Bunch of Security Updates for 2016-2022 Just Dropped. July 9, 2025
  • New Security Patches for SQL Server 2022, 2019, 2017, and 2016 October 8, 2024
  • Announcing SQL Server 2022 CU14 July 23, 2024
  • Security Update to Avoid Remote Code Execution July 10, 2024

© Brent Ozar Unlimited®. All Rights Reserved. Privacy Policy