Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
CVE-2024-37337
7.1HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2024-37337?
The Microsoft SQL Server Native Scoring vulnerability allows for potential exposure of sensitive information through improper access controls. This may affect data confidentiality, enabling unauthorized users to retrieve confidential data unintentionally, which poses a risk to data integrity and enterprise security practices. Organizations using the affected versions need to assess their security measures and implement the necessary updates.
Affected Version(s)
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3475.1
Microsoft SQL Server 2017 (GDR) x64-based Systems 14.0.0 < 14.0.2060.1
Microsoft SQL Server 2019 (CU 28) x64-based Systems 15.0.0 < 15.0.4390.2