First published: Tue Feb 14 2023(Updated: )
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server | =2008-sp4 | |
Microsoft SQL Server | =2008_r2-sp3 | |
Microsoft SQL Server | =2012-sp4 | |
Microsoft SQL Server | =2014-sp3 | |
Microsoft SQL Server | =2016-sp3 | |
Microsoft SQL Server | =2017 | |
Microsoft SQL Server | =2019 | |
Microsoft SQL Server | =2022 | |
Microsoft SQL Server 2008 for x64-Based Systems | ||
Microsoft SQL Server 2008 | ||
Microsoft SQL Server 2012 | ||
Microsoft SQL Server 2012 | ||
Microsoft SQL Server 2008 R2 for 32-Bit Systems | ||
Microsoft SQL Server 2008 R2 for x64-Based Systems | ||
Microsoft SQL Server 2014 (CU 4) | ||
Microsoft SQL Server 2014 (CU 4) | ||
Microsoft SQL Server 2014 | ||
Microsoft SQL Server 2014 | ||
Microsoft SQL Server 2019 (CU 18) | ||
Microsoft SQL Server 2017 (CU 31) | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2019 | ||
Microsoft SQL Server 2017 | ||
Microsoft SQL Server 2016 Azure Connect Feature Pack | ||
Microsoft SQL Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21718 is a remote code execution vulnerability in Microsoft ODBC Driver for SQL Server.
Microsoft SQL Server 2008 (SP4), 2008 R2 (SP3), 2012 (SP4), 2014 (SP3), 2016 (SP3), 2017, 2019, and 2022 are affected.
CVE-2023-21718 has a severity rating of 7.8 (high).
You can fix CVE-2023-21718 by applying the relevant security patches provided by Microsoft.
You can find more information about CVE-2023-21718 on the Microsoft Security Response Center website.