SERVER-MSSQL -- Snort has detected traffic exploiting vulnerabilities in Microsoft SQL Server servers.
SERVER-MSSQL Microsoft SQL remote code execution attempt
This rule looks for a malformed disk path specification in SQL commands that use a TO or FROM clause with a DISK keyword, where the drive letter is not followed by a path separator. Successful exploitation could allow an attacker to execute arbitrary code on the database server.
This rule fires on attempts to exploit a remote code execution vulnerability in Microsoft SQL Server instances.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Rule Categories::Server::SQL Server
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Vulnerability::Severity::Medium
Command Injection
Command Injection attacks target applications that allow unsafe user-supplied input. Attackers transmit this input via forms, cookies, HTTP headers, etc. and exploit the applications permissions to execute system commands without injecting code.
CVE-2019-1068 |
Loading description
|