CVE-2025-55227

Published Sep 9, 2025

Last updated 6 months ago

Overview

Description
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sql_server_2016, sql_server_2017, sql_server_2019, sql_server_2022

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-77

Social media

Hype score
Not currently trending
  1. #SQLServer vulnerabilities CVE-2025-55227 & CVE-2025-47997 may seem "Less Likely" to be exploited, but don't count on it. A vendor's unpatched database could be your next breach. Get a free eval and an attacker-centric view to find these blind spots: https://t.co/LUfuJHVpzs #

    @threatngsec

    19 Sept 2025

    111 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  2. ⚠️Actualizaciones de seguridad mensuales de Microsoft ❗CVE-2025-55232 ❗CVE-2025-55227 ❗CVE-2025-55234 ➡️Más info: https://t.co/m71z9xeyXb https://t.co/439OhGO7DK

    @CERTpy

    12 Sept 2025

    140 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Microsoft Patch Advisory – Sep 2025 🚨 100+ flaws fixed, incl. Critical RCEs & EoPs across Azure, SQL Server, Windows, Hyper-V & Office. ⚠️ High-risk CVEs: CVE-2025-54914 (Azure Networking, CVSS 10) CVE-2025-55227 (SQL Server, 8.8) 🛡️ Patch now. https:

    @sequretek_sqtk

    10 Sept 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-55227 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. https://t.co/3Pa98R1Edb

    @CVEnew

    9 Sept 2025

    160 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🔒 Confused about CVE-2025-55227? You’re not alone! The real star is CVE-2025-53727—a sneaky SQL flaw fixed in August 2025. Elevate your privilege knowledge, not your stress! #WindowsForum #SQLServer #CVE2025 https://t.co/wyZs4BEQnO

    @windowsforum

    9 Sept 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.