CVE-2023-21718: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.6814.4Patch KB5020863 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.50.6785.2Patch KB5021112 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.7512.11Patch KB5021123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.6174.8Patch KB5021045 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7024.30Patch KB5021128 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4280.7Patch KB5021124 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3460.9Patch KB5021126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.0.6444.4Patch KB5021037 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1050.5Patch KB5021522 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6430.49Patch KB5021129 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2101.7Patch KB5021125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2047.8Patch KB5021127
Event History
Frequently Asked Questions
What is CVE-2023-21718?
CVE-2023-21718 is a remote code execution vulnerability in Microsoft ODBC Driver for SQL Server.
What software versions are affected by CVE-2023-21718?
Microsoft SQL Server 2008 (SP4), 2008 R2 (SP3), 2012 (SP4), 2014 (SP3), 2016 (SP3), 2017, 2019, and 2022 are affected.
What is the severity of CVE-2023-21718?
CVE-2023-21718 has a severity rating of 7.8 (high).
How can I fix CVE-2023-21718?
You can fix CVE-2023-21718 by applying the relevant security patches provided by Microsoft.
Where can I find more information about CVE-2023-21718?
You can find more information about CVE-2023-21718 on the Microsoft Security Response Center website.