Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka SQL RDBMS Engine Elevation of Privilege Vulnerability.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sql_server | Microsoft | 2014-sp1 (including) | 2014-sp1 (including) |
| Sql_server | Microsoft | 2014-sp2 (including) | 2014-sp2 (including) |
| Sql_server | Microsoft | 2016 (including) | 2016 (including) |