Description
This module executes an arbitrary native payload on a Microsoft SQL server by loading a custom SQL CLR Assembly into the target SQL installation, and calling it directly with a base64-encoded payload.
The module requires working credentials in order to connect directly to the MSSQL Server.
This method requires the user to have sufficient privileges to install a custom SQL CRL DLL, and invoke the custom stored procedure that comes with it.
This exploit does not leave any binaries on disk.
Tested on MS SQL Server versions: 2005, 2012, 2016 (all x64).
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/mssql/mssql_clr_payloadmsf undefined(mssql_clr_payload) > show actions ...actions...msf undefined(mssql_clr_payload) > set ACTION < action-name >msf undefined(mssql_clr_payload) > show options ...show and set options...msf undefined(mssql_clr_payload) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub