{"id":1980,"date":"2025-02-14T10:03:37","date_gmt":"2025-02-14T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/14\/postgresql-terminal-tool-injection-vulnerability-allows-remote-code-execution\/"},"modified":"2025-02-14T10:03:37","modified_gmt":"2025-02-14T10:03:37","slug":"postgresql-terminal-tool-injection-vulnerability-allows-remote-code-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/14\/postgresql-terminal-tool-injection-vulnerability-allows-remote-code-execution\/","title":{"rendered":"PostgreSQL Terminal Tool Injection Vulnerability Allows Remote Code Execution"},"content":{"rendered":"<p>    PostgreSQL Terminal Tool Injection Vulnerability Allows Remote Code Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Researchers have uncovered a high-severity SQL injection vulnerability, CVE-2025-1094, affecting PostgreSQL\u2019s interactive terminal tool, psql.\u00a0<\/p>\n<p>This flaw was identified during research into the exploitation of CVE-2024-12356, a remote code execution (RCE) vulnerability in <a href=\"https:\/\/cybersecuritynews.com\/beyondtrust-privileged-remote-access-vulnerability-actively-exploited-in-the-wild\/\" target=\"_blank\" rel=\"noreferrer noopener\">BeyondTrust Privileged Remote Access (PRA)<\/a> and Remote Support (RS) products.\u00a0<\/p>\n<p>The discovery highlights the interconnected nature of these vulnerabilities, as successful exploitation of CVE-2024-12356 required leveraging CVE-2025-1094 in all tested scenarios.<\/p>\n<h2 class=\"wp-block-heading\"><strong>PostgreSQL Terminal Tool Injection Vulnerability<\/strong><\/h2>\n<p>CVE-2025-1094 arises from an incorrect assumption about the security of escaped untrusted input in PostgreSQL\u2019s string escaping routines.\u00a0<\/p>\n<p>It was believed that properly escaped input could not lead to <a href=\"https:\/\/cybersecuritynews.com\/zohocorp-manageengine-adaudit-plus-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">SQL injection attacks<\/a>. However, when invalid UTF-8 characters are processed by psql, attackers can exploit this flaw to inject malicious SQL statements.\u00a0<\/p>\n<p>This vulnerability has a CVSS 3.1 base score of 8.1, indicating high severity. Attackers can exploit this vulnerability to execute arbitrary SQL statements and achieve arbitrary code execution (ACE) by leveraging psql\u2019s meta-command functionality.\u00a0<\/p>\n<p>Meta-commands, identified by the exclamation mark (!), allow the execution of operating system shell commands directly from the interactive tool.<\/p>\n<p>This vulnerability was found by Stephen Fewer, Principal Security Researcher at Rapid7. CVE-2025-1094 plays a critical role in enabling remote code execution via <a href=\"https:\/\/cybersecuritynews.com\/beyondtrust-zero-day-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2024-12356<\/a>.\u00a0<\/p>\n<p>BeyondTrust patched CVE-2024-12356 in December 2024, blocking its exploitation path and indirectly mitigating attacks involving CVE-2025-1094.\u00a0<\/p>\n<p>However, this patch did not address the root cause of CVE-2025-1094, leaving it as a <a href=\"https:\/\/cybersecuritynews.com\/windows-driver-zero-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerability<\/a> until Rapid7\u2019s disclosure<\/p>\n<p>The vulnerability affects all supported <a href=\"https:\/\/cybersecuritynews.com\/postgresql-security-update-patch-for-multiple-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">PostgreSQL <\/a>versions prior to 17.3, 16.7, 15.11, 14.16 and 13.19.<\/p>\n<p>The flaw allows attackers to prematurely terminate SQL statements and inject additional commands. <\/p>\n<p>Exploitation can lead to significant risks, including unauthorized database access and full system compromise through shell command execution.<\/p>\n<h2 class=\"wp-block-heading\">\n<strong>Mitigation<\/strong>s<\/h2>\n<p>To mitigate CVE-2025-1094, PostgreSQL users should <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2025\/02\/13\/cve-2025-1094-postgresql-psql-sql-injection-fixed\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">upgrade<\/a> their installations to the latest patched versions:<\/p>\n<ul class=\"wp-block-list\">\n<li>PostgreSQL 17.3<\/li>\n<li>PostgreSQL 16.7<\/li>\n<li>PostgreSQL 15.11<\/li>\n<li>PostgreSQL 14.16<\/li>\n<li>PostgreSQL 13.19<\/li>\n<\/ul>\n<p>The PostgreSQL Global Development Group has issued advisories detailing the fixes and providing guidance on security practices.<\/p>\n<p>A Metasploit module targeting CVE-2025-1094 has been developed, enabling exploitation against vulnerable <a href=\"https:\/\/cybersecuritynews.com\/beyondtrust-remote-access-support-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">BeyondTrust systems<\/a>. This underscores the urgency for organizations to apply patches promptly.<\/p>\n<p>Organizations using PostgreSQL should act swiftly to patch their systems and review their security protocols to prevent exploitation of such vulnerabilities in the future.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>PCI DSS 4.0 &amp; Supply Chain Attack Prevention \u2013\u00a0<a href=\"https:\/\/webinars.indusface.com\/reducing-3rd-party-risks-pci-dss-and-supply-chain-attack-prevention\/register?utm_source=gbhackers-side-banner&amp;utm_campaign=2025-feb-webinar-pci-dss&amp;utm_medium=referral\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/postgresql-terminal-tool-injection-vulnerability\/\">PostgreSQL Terminal Tool Injection Vulnerability Allows Remote Code Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/postgresql-terminal-tool-injection-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PostgreSQL Terminal Tool Injection Vulnerability Allows Remote Code Execution Researchers have uncovered a high-severity SQL injection vulnerability, CVE-2025-1094, affecting PostgreSQL\u2019s interactive terminal tool, psql.\u00a0 This flaw was identified during research into the exploitation of CVE-2024-12356, a remote code execution (RCE) vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products.\u00a0 The discovery highlights [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-1980","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1980"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1980"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1980\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}