Exploitation of MSSQL xp_cmdshell for Persistence and Execution
Attackers can leverage the Microsoft SQL Server xp_cmdshell extended stored procedure to execute arbitrary OS commands, facilitating privilege escalation and persistence.
Microsoft SQL Server (MSSQL) includes extended stored procedures designed to extend database functionality, such as interfacing with external programs. One such procedure, xp_cmdshell, spawns a Windows command shell to execute strings passed as arguments. Because this procedure runs with the same security context as the MSSQL Server service account, it often executes with high privileges. While xp_cmdshell is disabled by default in standard configurations, attackers who successfully compromise a SQL server frequently enable this feature to execute arbitrary system commands, establish persistence, or conduct further post-exploitation activities. This technique is a common vector for adversaries looking to transition from database-level access to full operating system control. Defenders should scrutinize any process spawning from sqlservr.exe, especially when involving command-line interpreters or administrative tools.
Attack Chain
- Initial access is gained to the SQL server instance (e.g., via brute force or web application vulnerability).
- The attacker uses SQL queries to alter the server configuration (e.g., 'sp_configure') to enable the 'show advanced options' setting.
- The attacker enables the 'xp_cmdshell' feature within the SQL Server configuration.
- The attacker invokes 'xp_cmdshell' via a T-SQL command to execute a malicious payload.
- The 'sqlservr.exe' process spawns a child process, such as 'cmd.exe', 'powershell.exe', or other binaries.
- The spawned process executes arbitrary commands, such as downloading additional malware, modifying system files, or creating local administrative users.
- The attacker leverages these commands to establish long-term persistence on the host.
Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the MSSQL service account. This can result in full system compromise, exfiltration of sensitive database content, deployment of ransomware, or the establishment of persistent backdoors on the affected Windows server.
Recommendation
Prioritize the following actions to detect and mitigate unauthorized use of xp_cmdshell:
- Disable the xp_cmdshell stored procedure on all SQL servers unless there is a documented business requirement.
- Implement strict allowlists for processes spawned by 'sqlservr.exe' using the provided detection rules.
- Audit configuration changes for SQL servers to identify unauthorized attempts to toggle 'xp_cmdshell'.
- Restrict SQL Server service account permissions to the minimum necessary for database operations to limit the impact of code execution.
- Ensure SQL servers are not directly reachable from the internet to prevent unauthenticated access.
- Deploy the Sigma rules below to monitor for suspicious process creation originating from the SQL server process tree.
Immediate actions
Review all SQL server configurations to confirm xp_cmdshell is disabled.
Threat Hunt
Search for process execution logs where ParentImage is sqlservr.exe.
Data: Process creation events (Event ID 1)
Mitigations
Disable xp_cmdshell stored procedure.
T1505.001
Detection coverage 1
Detect Execution via MSSQL xp_cmdshell
mediumDetects suspicious process creation stemming from the SQL Server process, which may indicate the use of xp_cmdshell for unauthorized code execution.
Detection queries are available on the platform. Get full rules →