Impact
The vulnerability allows an attacker with authorized access to execute improperly sanitized SQL statements, resulting in a SQL injection that elevates their privileges within Azure SQL Database. The flaw is defined as CWE-89. By injecting malicious sql, an attacker can gain higher database permissions, potentially accessing or modifying data beyond their intended scope.
Affected Systems
Microsoft Azure SQL Database instances are impacted. No specific version constraints are listed, suggesting that all current releases may be affected until Microsoft releases a fix.
Risk and Exploitability
The CVSS score of 9.9 classifies this flaw as Critical. EPSS is marked as not available, so the probability of exploitation cannot be quantified at this time, but the flaw is not listed in the CISA KEV catalog. Likely, exploitation requires a legitimate user account or a user with network connectivity to the database, after which the SQL injection can be used to gain elevated privileges.
OpenCVE Enrichment