SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49013
8.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 November 2024
What is CVE-2024-49013?
The vulnerability in SQL Server Native Client allows for the execution of arbitrary code, granting attackers potential control over affected systems. This could lead to the compromise of confidential information, execution of unauthorized commands, and overall disruption of services. It is crucial for organizations using this software to assess their environments and implement recommended security measures promptly to safeguard against potential exploitation.
Affected Version(s)
Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1