SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49009
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 November 2024
What is CVE-2024-49009?
The SQL Server Native Client contains a vulnerability that allows remote code execution. This occurs when the client improperly handles certain requests sent to it, potentially enabling an attacker to execute arbitrary code on the host system. Successful exploitation of this vulnerability requires that an attacker sends specially crafted requests to the SQL Server Native Client, which could lead to unauthorized access and system compromise. It is crucial for users and administrators to apply recommended security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1