Andreas Wolter 10/30/2018

Privilege Escalation to sysadmin via Trustworthy Database setting

Read Original

This technical blog post details a SQL Server security vulnerability where the 'Trustworthy' database setting, combined with a high-privilege database owner and certain user permissions, can enable an attacker to escalate privileges to sysadmin. It is a warning for administrators and developers, explaining the prerequisites and attack vector, which remains relevant despite being known for years.

Privilege Escalation to sysadmin via Trustworthy Database setting

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week