The point is that it is exploitable from SQL, therefore is also exploitable from the application that is creating the database.
This would be a target for a sql injection exploit and so is remotely exploitable
This would be a target for a sql injection exploit and so is remotely exploitable
As a standalone issue I agree with the GP comment - this bug is not a RCE issue, it's privilege escalation.