Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2023-21718
Key Information:
Summary
A remote code execution vulnerability exists when the Microsoft ODBC Driver for SQL Server improperly handles objects in memory. An attacker who successfully exploits this vulnerability could run arbitrary code on the affected system. To exploit the vulnerability, an attacker would need to send a specially crafted request to the SQL Server, potentially compromising the confidentiality, integrity, and availability of affected systems. Users are advised to update to the latest version to mitigate risk.
Affected Version(s)
Microsoft SQL Server 2008 R2 Service Pack 3 (QFE) x64-based Systems 10.0.0 < 10.50.6785.2
Microsoft SQL Server 2008 Service Pack 4 (QFE) 32-bit Systems 10.0.0 < 10.0.6814.4
Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE) x64-based Systems 11.0.0 < 11.0.7512.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved