SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21332
8.8HIGH
Key Information:
Summary
This vulnerability exists in the SQL Server Native Client OLE DB Provider, allowing attackers to execute arbitrary code on the affected system when the client processes specially crafted requests. Successful exploitation could lead to unauthorized actions and data breaches, highlighting the importance of timely updates and system monitoring in cybersecurity frameworks.
Affected Version(s)
Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6441.1
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7037.1
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3471.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed