Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2024-49021

7.8HIGH

Summary

Microsoft SQL Server has been identified with a Remote Code Execution vulnerability that poses significant risks by enabling attackers to execute arbitrary code on affected installations. When exploited, this vulnerability can lead to unauthorized access and control over database management systems, potentially compromising sensitive data. The affected versions include SQL Server 2016, 2017, 2019, and 2022, underscoring the need for users to apply necessary security patches to mitigate the risks. For more detailed information, refer to the vendor advisory.

Affected Version(s)

Microsoft SQL Server 2016 Service Pack 3 (GDR) x64-based Systems 13.0.0 < 13.0.6455.2

Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack x64-based Systems 13.0.0 < 13.0.7050.2

Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3485.1

References

EPSS Score

0% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.