KB5068403: This update resolves an issue in SQL Server Analysis Services
KB5068403 - Description of the security update for SQL Server 2017 GDR: November 11, 2025
Improvements and fixes included in this update
4653635:
- This update resolves an issue in SQL Server Analysis Services where Row-Level Security (RLS) filters could be skipped when combined with Object-Level Security (OLS) and Column-Level Security (CLS) in certain multi-role configurations. This only occurs under rare and contradictory setups (for example, a role granting table-level read permission while restricting all columns, combined with other similar restrictive roles). The fix ensures RLS is consistently applied in all scenarios.
4711204:
- This hotfix addresses a SQL injection vulnerability in an internal backup stored procedure, that was inadvertently exposed to all users. The hotfix restricts unauthorized access and mitigates the risk by properly sanitizing input parameters.

