Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a vulnerability in Anyquery, a SQL query engine, that could allow an unauthenticated remote attacker to create or overwrite files on the server. While the primary impact is loss of filesystem integrity and denial of service, remote code execution is a possibility under certain conditions. The main concern is confirming if Anyquery is in use and if it is exposed to external networks.
- Unauthenticated attackers can write files on the server.
- Allows system compromise and denial of service.
- Confirm Anyquery use and network exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by connecting to the Anyquery server's MySQL-compatible port over the network. Because the server forwards unauthenticated SQL queries to SQLite without restricting filesystem targets, the attacker can instruct the server to create a database file in any location writable by the Anyquery process. This enables the attacker to add controlled data to the new file, potentially leading to arbitrary file creation or overwrite, denial of service, and in some scenarios, remote code execution.
- No authentication required for access.
- Attacker controls SQL queries to the server.
- Filesystem integrity loss and DoS risk.
Live Threat
Current exploitation, exposure, and threat context
A remote attacker could exploit this vulnerability by sending unauthenticated SQL queries to the Anyquery server. When supported by the advisory, this could allow the attacker to write arbitrary files to the server's filesystem, potentially leading to a denial of service or even remote code execution if another service interprets the created file or the process has a privileged writable target.
- Filesystem integrity loss and denial of service.
- Attacker writes files via SQL injection.
- Arbitrary file creation or overwrite.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for the Anyquery server, likely application or platform owners, must first identify all instances of this SQL query engine. Confirming network reachability and business criticality for each instance will inform prioritization. The next step is to locate the accountable owner and plan remediation, considering any external dependencies or potential impact on filesystem integrity.
- Identify Anyquery instances and owners.
- Verify network exposure and business criticality.
- Plan remediation based on risk assessment.