Impact
Vulnerability in the replication component of Oracle MySQL Server and Cluster permits a high privileged attacker who has logged into the host that runs MySQL to gain full control of the database instance. By exploiting this flaw an attacker can compromise the confidentiality, integrity, and availability of all data managed by MySQL. The flaw is characterized by a CVSS v3.1 base score of 6.4 with a vector indicating local attack, high attack complexity, and high privileges.
Affected Systems
Affected products include Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as Oracle MySQL Cluster versions 8.0.0 to 8.0.47, 8.4.0 to 8.4.10, and 9.7.0 to 9.7.1. Any deployment using these versions that runs a replication component is subject to the risk described.
Risk and Exploitability
Although the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, the impact of a successful exploitation is significant. The exploit requires that the attacker already has local high‑privileged access to the host; from there the compromised MySQL instance can be taken over. The moderate CVSS score indicates a meaningful risk, and due to the severe consequences, timely remediation is recommended.
OpenCVE Enrichment