CVE-2025-62575
BaseFortify
Publication date: 2025-12-02
Last updated on: 2025-12-04
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | sql_server | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists because NMIS/BioDose versions 22.02 and earlier use a Microsoft SQL Server database where the SQL user account 'nmdbuser' and other created accounts are assigned the sysadmin role by default. This excessive privilege allows an attacker to execute remote code by exploiting certain built-in stored procedures in the database.
How can this vulnerability impact me? :
The vulnerability can lead to remote code execution on the affected system, which means an attacker could potentially take full control of the database server and possibly the underlying system. This could result in data theft, data manipulation, service disruption, or further compromise of the network.