#VU49489 Input validation error in Microsoft SQL Server - CVE-2021-1636
Published: January 12, 2021 / Updated: January 12, 2021
Microsoft SQL Server
Microsoft
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input, when the affected SQL Server is configured to run an Extended Event session. A remote user can send specially crafted data to the server and execute arbitrary code with elevated privileges.