SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
CVE-2024-21428

8.8HIGH

Summary

The SQL Server Native Client OLE DB Provider has a vulnerability that could allow an attacker to execute arbitrary code on a system through a specially crafted OLE DB request. This vulnerability can be exploited remotely, emphasizing the need for users to apply the necessary updates and apply security best practices. Ensuring your systems are patched against CVE-2024-21428 is crucial for maintaining the security and integrity of your SQL Server installations. Detailed guidance on mitigating this risk can be found in the applicable vendor advisory.

Affected Version(s)

Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6441.1

Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7037.1

Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3471.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.