CVE-2015-1761
Summary
| CVE | CVE-2015-1761 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-14 23:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authenticated users to gain privileges by leveraging certain write access, aka "SQL Server Elevation of Privilege Vulnerability." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Sql Server | 2008 | r2_sp2 | All | All |
| Application | Microsoft | Sql Server | 2008 | r2_sp3 | All | All |
| Application | Microsoft | Sql Server | 2008 | sp3 | All | All |
| Application | Microsoft | Sql Server | 2008 | sp4 | All | All |
| Application | Microsoft | Sql Server | 2012 | sp1 | All | All |
| Application | Microsoft | Sql Server | 2012 | sp2 | All | All |
| Application | Microsoft | Sql Server | 2014 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Security Bulletin MS15-058 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | |
| Microsoft SQL Server Bugs Let Remote Authenticated Users Gain Privilege Escalation and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.