SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49011
Summary
The vulnerability in SQL Server Native Client allows for potential remote code execution, enabling attackers to run arbitrary code in the context of the affected application. This issue arises from improper handling of specific data by the client, creating security risks in environments utilizing Microsoft SQL Server products. Organizations using SQL Server Native Client must implement patches and follow recommended security practices to safeguard against potential exploitation.
Affected Version(s)
Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published