SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49009
Summary
The SQL Server Native Client contains a vulnerability that allows remote code execution. This occurs when the client improperly handles certain requests sent to it, potentially enabling an attacker to execute arbitrary code on the host system. Successful exploitation of this vulnerability requires that an attacker sends specially crafted requests to the SQL Server Native Client, which could lead to unauthorized access and system compromise. It is crucial for users and administrators to apply recommended security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published