Impact
The Clone Plugin in Oracle MySQL Server and MySQL Cluster has been found to allow a local attacker with high‑privileged access to log on to the host machine to gain full control of the database service. The flaw grants the attacker the ability to compromise confidentiality, integrity and availability of the data stored in the affected MySQL installations, effectively enabling a complete database takeover.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as Oracle MySQL Cluster releases 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The described attack requires an attacker to already possess high‑privileged access on the host running the database, and the exploitation is considered difficult. A successful attack would allow full control over the database server, permitting data exfiltration, corruption and denial of service.
OpenCVE Enrichment