SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49013
8.8HIGH
Summary
The vulnerability in SQL Server Native Client allows for the execution of arbitrary code, granting attackers potential control over affected systems. This could lead to the compromise of confidential information, execution of unauthorized commands, and overall disruption of services. It is crucial for organizations using this software to assess their environments and implement recommended security measures promptly to safeguard against potential exploitation.
Affected Version(s)
Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed