QID 376382
Date Published: 2022-02-09
QID 376382: Microsoft SQL Server for Linux Containers Elevation of Privilege Vulnerability for February 2022
This vulnerability is not present on servers that are running SQL Server 2019 on Linux bare metal or VMs. This vulnerability is exposed only in SQL Server 2019 Linux container images.
CVE-2022-23276: SQL Server for Linux Containers Elevation of Privilege Vulnerability
SQL Server 2019 GDR, Customers who have deployed SQL Server 2019 Linux container images need to update SQL Server 15.0.2090.38. and Cumulative Update 15 for SQL Server 2019 version 15.0.4198.2.
Affected Software:
SQL Server version from 15.0.2090.0 through 15.0.2090.37.
SQL Server Version from 15.0.4198.0 through 15.0.4198.1
QID Detection Logic(Authenticate):
This QID will check the vulnerable version of SQL Server 2019 GDR on the Linux container.
Successful exploitation allows an attacker to perform escalation of privileges on the vulnerable machine.
- CVE-2022-23276 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23276
CVEs related to QID 376382
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5010657 |
|