Privilege Escalation to sysadmin via Trustworthy Database setting
Read OriginalThis technical blog post details a SQL Server security vulnerability where the 'Trustworthy' database setting, combined with a high-privilege database owner and certain user permissions, can enable an attacker to escalate privileges to sysadmin. It is a warning for administrators and developers, explaining the prerequisites and attack vector, which remains relevant despite being known for years.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser