HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-36417

CVSS 7.8v3.1pub. 2023-10-10upd. 2024-11-21

Microsoft SQL OLE DB Remote Code Execution Vulnerability

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Microsoft Ole Db Driver For Sql Server

    APP
    Microsoft
    18.0.0 – 18.6.0007.0 (excl.)19.0.0 – 19.3.0002.0 (excl.)
  • Microsoft SQL Server

    APP
    Microsoft
    20192022
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-8273CRITICAL9.8PL ✓same product

Buffer overflow umożliwiający RCE w Microsoft SQL Server

CVE-2020-0618HIGH8.8⚠ KEVsame product

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly ha...

CVE-2019-1068HIGH8.8⚠ KEVsame product

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of...

CVE-2012-1856HIGH8.8⚠ KEVsame product

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 ...

CVE-2024-37334HIGH8.8same product

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability