logo

Privilege Escalation in SQL Server (Depending on some dodgy requirements)

ID: f0d7aeab-aa53-5015-82e8-f1049538761f

STIX ID: report--f0d7aeab-aa53-5015-82e8-f1049538761f

Feed Name: SensePost Blog

Threat Score
30/100

Date Published: 2012-08-08

Date Updated: 2026-04-29

...
...

The author demonstrates that, due to default cross-database permission chaining between master, msdb, and tempdb, a user with the ability to create/alter stored procedures in [master].[dbo] can insert rows into msdb job tables to create SQL Server Agent jobs owned by 'sa'; PoC procedures for SQL2000/2005/2008 are provided, but the technique requires specific preconditions and the created jobs will not run until the SQL Server Agent cache is refreshed (typically after a restart).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.