A Remote Code Execution vulnerability (CVE-2019-1068) in Microsoft SQL Server 2014 onwards exists. This vulnerability is ranked as Important, and does require authentication. It is deemed as high risk vulnerability since it could be chained with SQL injection to allow an cyber attacker to completely compromise the server.
Date Discovered: 9 July 2019
Risk Rating: High
1. Run all software as a non-privileged user with minimal access rights.
To reduce the impact of latent vulnerabilities, always run non-administrative software as an unprivileged user with minimal access rights.
2. Deploy intrusion prevention systems to monitor network traffic for malicious activity.
Deploy IDS/IPS to monitor and block network traffic for signs of anomalous or suspicious activity. This includes but is not limited to requests that include NOP sleds and unexplained incoming and outgoing traffic. This may indicate exploit attempts or activity that results from successful exploits
3. Implement multiple layers of cyber defense.
Memory-protection schemes (such as non-executable stack and heap configurations and randomly mapped memory segments) will complicate exploits of memory-corruption vulnerabilities.
4. Deploy Microsoft updates.
Updates are available from Microsoft. Please refer to vendor website for further information.