SQL Server Local Authorization Bypass
Summary
Despite SQL Server 2008/2012 removing automatic sysadmin rights for local admins, NT AUTHORITY\SYSTEM keeps them, so attackers can psexec as SYSTEM and use osql for full database control.
- Published
- Collected
Skip to content