Bug in Auditing allows for undetected Data Exfiltration by low privileged user
Read OriginalThe article details a critical security vulnerability in Microsoft SQL Server's SENSITIVE_BATCH_COMPLETED audit action group. A low-privileged user with SELECT permissions can use commands like SELECT INTO or DBCC CLONEDATABASE to exfiltrate sensitive data without generating audit logs, bypassing detection. The author provides reproduction steps, discusses Microsoft's low-priority assessment, and offers temporary mitigation strategies until a fix is released.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser