Bug in Auditing allows for undetected Data Exfiltration by low privileged user
Read OriginalThe article details a critical security vulnerability in Microsoft SQL Server's SENSITIVE_BATCH_COMPLETED audit action group. A low-privileged user with SELECT permissions can use commands like SELECT INTO or DBCC CLONEDATABASE to exfiltrate sensitive data without generating audit logs, bypassing detection. The author provides reproduction steps, discusses Microsoft's low-priority assessment, and offers temporary mitigation strategies until a fix is released.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
1
Quoting Thariq Shihipar
Simon Willison
•
2 votes
2
Top picks — 2026 January
Paweł Grzybek
•
1 votes
3
In Praise of –dry-run
Henrik Warne
•
1 votes
4
Deep Learning is Powerful Because It Makes Hard Things Easy - Reflections 10 Years On
Ferenc Huszár
•
1 votes
5
Vibe coding your first iOS app
William Denniss
•
1 votes
6
AGI, ASI, A*I – Do we have all we need to get there?
John D. Cook
•
1 votes
7
Dew Drop – January 15, 2026 (#4583)
Alvin Ashcraft
•
1 votes