Security-issue: guest-guest impersonation
Read OriginalThe article details a security flaw in SQL Server (versions 2005-2008 R2) where enabling the guest account in multiple databases can lead to guest-guest impersonation. This allows a user (e.g., a developer) in one database to impersonate the local guest, connect to another database with guest enabled, and gain unauthorized permissions, bypassing explicit denials. The issue was reported to Microsoft, with a fix expected only in a future major release (codename 'Denali').
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
1
Quoting Thariq Shihipar
Simon Willison
•
2 votes
2
Top picks — 2026 January
Paweł Grzybek
•
1 votes
3
In Praise of –dry-run
Henrik Warne
•
1 votes
4
Deep Learning is Powerful Because It Makes Hard Things Easy - Reflections 10 Years On
Ferenc Huszár
•
1 votes
5
Vibe coding your first iOS app
William Denniss
•
1 votes
6
AGI, ASI, A*I – Do we have all we need to get there?
John D. Cook
•
1 votes
7
Dew Drop – January 15, 2026 (#4583)
Alvin Ashcraft
•
1 votes