CVE-2026-22306RCE en Ozols SQL por dominio de actualización abandonado
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
Ver en NVDAnálisis
Ozols SQL en Windows descarga actualizaciones sin cifrado ni verificación de integridad a través de un dominio abandonado. Un atacante puede suplantar el servidor de actualizaciones para ejecutar código arbitrario en el sistema y bases de datos afectadas mediante el componente OzolsSQL.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-319CWE-494CWE-829EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.