Maintained with ☕️ by
IcePanel logo

Cloud SQL for SQL Server - June 2nd, 2023 [Security]

Share

Services

## Security A vulnerability was recently discovered in Cloud SQL for SQL Server that allowed customer administrator accounts to create triggers in the `tempdb` database and use those to gain `sysadmin` privileges in the instance. The `sysadmin` privileges would give the attacker access to system databases and partial access to the machine running that SQL Server instance. Google Cloud resolved the issue by patching the security vulnerability by March 1, 2023\. Google Cloud didn't find any compromised customer instances. For instructions and more details, see the [Cloud SQL security bulletin](https://cloud.google.com/sql/docs/security-bulletins#gcp-2023-007).