CVE-2023-21713: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.7512.11Patch KB5021123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.6174.8Patch KB5021045 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4280.7Patch KB5021124 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2047.8Patch KB5021127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1050.5Patch KB5021522 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3460.9Patch KB5021126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.6444.4Patch KB5021037 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6430.49Patch KB5021129 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2101.7Patch KB5021125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7024.30Patch KB5021128
Event History
Frequently Asked Questions
What is CVE-2023-21713?
CVE-2023-21713 is a Microsoft SQL Server Remote Code Execution Vulnerability.
Which versions of Microsoft SQL Server are affected?
Microsoft SQL Server 2012 (sp4), 2014 (sp3), 2016 (sp3), 2017, 2019, and 2022 are affected.
What is the severity of CVE-2023-21713?
CVE-2023-21713 has a severity rating of 8.8 (high).
How can I fix CVE-2023-21713?
Apply the appropriate patches or updates provided by Microsoft for your version of SQL Server.
Where can I find more information about CVE-2023-21713?
You can find more information about CVE-2023-21713 on the Microsoft Security Response Center website.