Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

SQL Server Local Authorization Bypass

Summary

Despite SQL Server 2008/2012 removing automatic sysadmin rights for local admins, NT AUTHORITY\SYSTEM keeps them, so attackers can psexec as SYSTEM and use osql for full database control.
Published
Collected

original ↗