
If the database runs with administrator permissions on Microsoft SQL Server, the account also has the ability to execute commands on the system, so the SQL injection becomes a remote code execution vector. Another user confirmed on X that they were able to reproduce the flaw in a non-default configuration.
“Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses,” researchers from security firm watchTowr told CSO via email on Thursday. “Yet another example of how quickly attackers move once a vulnerability enters the public domain.”
So far, the researchers haven’t seen any malicious payloads or commands being sent, and the attempts look more like probes to identify vulnerable GeoServer instances. However, this is likely to change; GeoServer has a history of being exploited, since its users are usually seen as high value targets.
