Executive brief
Microsoft Entra Connect Sync is a service that synchronizes identity and access data between on-premises Active Directory and Azure AD. An SQL injection vulnerability in this component allows an authorized attacker with local access to execute arbitrary SQL commands and escalate their privileges on the system.
Technical details
The vulnerability is an SQL injection flaw in Microsoft Entra Connect Sync that results from improper neutralization of special SQL characters in user-supplied input. An authorized attacker with local access to the system can craft malicious SQL commands to inject arbitrary code into database queries. Successful exploitation allows privilege escalation to gain higher-level system or database permissions. The flaw requires local system access and prior authorization, limiting the attack surface to insider threats or compromised local accounts.
Affected products
- Microsoft Entra Connect Sync
Timeline
- 2026-08-11: disclosed