Ir al contenido
CodeAuditAgent

CVE-2026-32167

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Debilidad

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Productos afectados

  • microsoft sql_server_2016
  • microsoft sql_server_2017
  • microsoft sql_server_2019
  • microsoft sql_server_2022
  • microsoft sql_server_2025

Referencias

Encuentra el fallo antes que un atacante.

Inicia sesión con GitHub y ejecuta tu primera auditoría en menos de un minuto. El plan gratuito no requiere tarjeta de crédito.