RULE(RULE ID:1605123)

Rule General Information
Release Date: 2016-12-20
Rule Name: Microsoft SQL RDBMS Engine UNC Path Injection Privilege Escalation Vulnerability -2 (CVE-2016-7250)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."
Impact: An attacker can abtain more privileges which he is not entitled to by exloiting the vulnerability, such as executing arbitrary code, deleting files, viewing sensitive information, changing configurations.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS16-136
SecurityFocusBID:94060
SecurityTrackerID:1037250
Solutions
Microsoft has released a patch MS16-136 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS16-136