Skip to main content

Security updates released for PostgreSQL

Proof-of-concept exploit code released for SQL injection vulnerability CVE-2025-1094

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Proof-of-concept exploit code released for SQL injection vulnerability CVE-2025-1094


Threat details

Potential Exploitation of CVE-2025-1094

Security researchers have published a demonstration of the exploitation of CVE-2025-1094 to achieve arbitrary code execution with privileges of the current site user. When applied on a remote access agent, CVE-2025-1094 can achieve remote code execution. This tactic had been observed in an attack chain alongside the BeyondTrust Remote Support vulnerability, CVE-2024-12356 (detailed in Cyber Alert CC-4591) indicating the ability to exploit this vulnerability by attackers. The attack has also been incorporated into a red-teaming tool which enables automated exploitation of vulnerable instances. The NHS England National CSOC assesses further exploitation in the wild to be almost certain.

Out-of-cycle release scheduled for 20 February 2025

Following the security fix for CVE-2025-1094, a regression has been introduced, which may result in errors. The regression bug has since been fixed with additional new releases of PostgreSQL. Please see the update from PostgreSQL for more information.


Introduction

The PostgreSQL Global Development Group (also known as Postgres) has released an advisory to address a high severity vulnerability in PostgreSQL. PostgreSQL is a relational SQL database management system.

CVE-2025-1094 is an 'improper neutralisation of quoting syntax' vulnerability with a CVSSv3 score of 8.1. A remote unauthenticated attacker could execute arbitrary code with the privileges of the current site user by sending a specially crafted SQL statement. When exploited on a remote access agent, an attacker may achieve remote code execution.

Proof-of-concept code has been released for CVE-2025-1094.


Threat updates

Date Update
21 Feb 2025 Cyber Alert updated to cover the new PostgreSQL release which fixes the regression bug from the security update.
18 Feb 2025 Clarification of impact and out-of-cycle release announcement added

Remediation advice

Affected organisations are encouraged to review PostgreSQL's CVE-2025-1094 security advisory and apply the relevant updates as soon as practicable.



Last edited: 21 February 2025 1:08 pm