SQL Server Check

External scripts enabled

This is one of many SQL Server checks performed by our free sp_Check tools.

Learn More About Our sp_check Tools

Checks Performed

ID
Check
369
External scripts enabled

What’s the issue?

SQL Server Machine Learning Services allows R, Python, and Java code to be executed inside the database engine through the sp_execute_external_script stored procedure. The feature is controlled by the external scripts enabled server configuration option, which is off by default.

When enabled, script execution is handled by the Launchpad service, which runs the external runtime in a separate process under a dedicated set of worker accounts rather than under the SQL Server service account itself.

Why is this a problem?

External scripts run general-purpose code with access to the runtime’s full standard library. Depending on the language and the packages installed, that can include file system access, network calls, and the ability to launch processes, all of which are well beyond what T-SQL alone can do.

The feature also expands the impact of a SQL injection vulnerability. An attacker who reaches the database through an application flaw gains a path to execute arbitrary R or Python rather than being limited to database operations, which shortens the distance between an injection and code execution on the host.

The configuration may also be enabled but unused. Machine Learning Services is frequently installed and enabled during evaluation or as part of a project that may now bee ended, leaving the surface area available with no offsetting benefit and no one monitoring how it is used.

What should you do about this?

Determine whether the feature is actually in use by reviewing stored procedures, jobs, and application code for calls to sp_execute_external_script, and by checking whether the Launchpad service is running and configured to start automatically.

Disable the feature with EXEC sp_configure 'external scripts enabled', 0; RECONFIGURE; if it is not being used, and plan a service restart for the change to take effect. Consider removing the Machine Learning Services feature entirely if no future need is expected.

Where external scripts are genuinely required, restrict EXECUTE ANY EXTERNAL SCRIPT permission to only the principals that need it, review the packages installed in each runtime, and confirm the Launchpad worker accounts hold only the host permissions the workload requires.

Type

Security

Importance

Medium

sp_Checks