About this tag
Execution risk in the context of Windows and Microsoft SQL Server refers to vulnerabilities that could allow remote code execution when an authenticated attacker runs a specially crafted query. This risk is highlighted in security updates like MS15-058, which addresses flaws where a virtual function is called from a wrong address, leading to function calls to uninitialized memory. Such execution risks require the attacker to have permissions to create or modify a database. Understanding execution risk is crucial for database administrators and IT security professionals to prioritize patching and mitigate potential exploits that could compromise system integrity.
-
MS15-058 - Important: Vulnerabilities in SQL Server Could Allow Remote Code Execution...
Severity Rating: Important Revision Note: V1.0 (July 14, 2015): Bulletin published Summary: This security update resolves vulnerabilities in Microsoft SQL Server. The most severe vulnerabilities could allow remote code execution if an authenticated attacker runs a specially crafted query that is...- News
- Thread
- 2015 attacker authentication database execution risk function call memory management ms15-058 patch query execution remote code execution revision note security server security sql server technet technical bulletin update vulnerability
- Replies: 0
- Forum: Security Alerts