SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49009

8.8HIGH

Summary

The SQL Server Native Client contains a vulnerability that allows remote code execution. This occurs when the client improperly handles certain requests sent to it, potentially enabling an attacker to execute arbitrary code on the host system. Successful exploitation of this vulnerability requires that an attacker sends specially crafted requests to the SQL Server Native Client, which could lead to unauthorized access and system compromise. It is crucial for users and administrators to apply recommended security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2

Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2

Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1

References

EPSS Score

0% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.