Impact
This vulnerability is an SQL Injection flaw that occurs because special elements in an SQL command are not properly neutralized. An attacker who already has authorized access to an Azure SQL Database instance can exploit the flaw to elevate their privileges over the database network. The result is an elevated level of control within the database that can lead to unauthorized data access or modification.
Affected Systems
Microsoft Azure SQL Database is affected. No specific version information is listed, so all instances of Azure SQL Database are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network connection from an authorized user; the attacker needs legitimate credentials to connect to the database and then craft a malicious query to gain elevated privileges. Because the flaw directly allows the attacker to manipulate the SQL engine, the risk of exploitation is high. The absence of a known exploitation probability metric does not reduce the obvious severity of the flaw.
OpenCVE Enrichment