Privilege Escalation in SQL Server (Depending on some dodgy requirements)
ID: f0d7aeab-aa53-5015-82e8-f1049538761f
STIX ID: report--f0d7aeab-aa53-5015-82e8-f1049538761f
Feed Name: SensePost Blog
Threat Score
The author demonstrates that, due to default cross-database permission chaining between master, msdb, and tempdb, a user with the ability to create/alter stored procedures in [master].[dbo] can insert rows into msdb job tables to create SQL Server Agent jobs owned by 'sa'; PoC procedures for SQL2000/2005/2008 are provided, but the technique requires specific preconditions and the created jobs will not run until the SQL Server Agent cache is refreshed (typically after a restart).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
