CVE-2023-21705: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.7512.11Patch KB5021123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4280.7Patch KB5021124 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3460.9Patch KB5021126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7024.30Patch KB5021128 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.6444.4Patch KB5021037 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6430.49Patch KB5021129 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.6174.8Patch KB5021045 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2047.8Patch KB5021127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1050.5Patch KB5021522 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2101.7Patch KB5021125
Event History
Frequently Asked Questions
What is CVE-2023-21705?
CVE-2023-21705 is a Microsoft SQL Server Remote Code Execution Vulnerability.
What is the severity of CVE-2023-21705?
The severity of CVE-2023-21705 is high with a CVSS score of 8.8.
Which versions of Microsoft SQL Server are affected by CVE-2023-21705?
Microsoft SQL Server 2012, 2014, 2016, 2017, 2019, and 2022 are affected by CVE-2023-21705.
How can I fix CVE-2023-21705?
To fix CVE-2023-21705, apply the relevant security patches provided by Microsoft.
Where can I find more information about CVE-2023-21705?
You can find more information about CVE-2023-21705 on the Microsoft Security Response Center website.