V-271188
Microsoft SQL Server 2022 Database Security Technical Implementation Guide
Title
Execution of stored procedures and functions that use execute as must be restricted to necessary cases only.
Description
<VulnDiscussion>In certain situations, to provide required functionality, a DBMS must execute internal logic (stored procedures, functions, triggers, etc.) and/or external code modules with elevated privileges. However, if the privileges required for execution are at a higher level than the privileges assigned to organizational users invoking the functionality applications/programs, those users are indirectly provided with greater privileges than assigned by organizations. Privilege elevation m...
Fix Text (Documentation Requirement)
Alter stored procedures and functions to remove the "EXECUTE AS" statement.