CVE-2021-1636
vulnerability analysis and mitigation

Overview

Microsoft SQL Server Elevation of Privilege Vulnerability (CVE-2021-1636) was disclosed on January 12, 2021. This vulnerability affects multiple versions of Microsoft SQL Server including SQL Server 2019, SQL Server 2017, SQL Server 2016 Service Pack 2, SQL Server 2014, and SQL Server 2012 Service Pack 4 (Microsoft KB).

Technical details

The vulnerability exists when data is sent over a network to an affected Microsoft SQL Server instance that may cause code to run against the SQL Server process if a certain extended event is enabled (Microsoft KB).

Impact

This vulnerability could allow an attacker to execute code against the SQL Server process, potentially leading to elevation of privilege (CVE Details).

Mitigation and workarounds

Microsoft has released security updates to address this vulnerability. The fixes are available through various security updates depending on the SQL Server version: KB4583458 for SQL Server 2019 GDR, KB4583459 for SQL Server 2019 CU8, KB4583456 for SQL Server 2017 GDR, KB4583457 for SQL Server 2017 CU22, KB4583460 for SQL Server 2016 SP2 GDR, KB4583461 for SQL Server 2016 SP2 CU15, KB4583463 for SQL Server 2014 SP3 GDR, KB4583465 for SQL Server 2012 SP4 GDR, and KB4583462 for SQL Server 2014 SP3 CU4 (Microsoft KB).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management