June 2, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

A vulnerability was discovered in Cloud SQL for SQL Server
that allowed customer administrator accounts to create triggers
in the tempdb database and use those to gain sysadmin privileges in the instance.
The sysadmin privileges would give the attacker access to system databases
and partial access to the machine running that SQL Server instance.

access accounts attacker cloud cloud sql customer database databases escalation gcp instance machine partial privilege privilege escalation privileges running server sql sql server sysadmin system vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC