First published: Tue Apr 11 2023(Updated: )
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft OLE DB Driver 18 for SQL Server | ||
Microsoft OLE DB Driver 19 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft Odbc | >=17.0<17.10.3.1 | |
Microsoft Odbc | >=18.0<18.2.1.1 | |
Microsoft Ole Db | >=18.0<18.6.5 | |
Microsoft Ole Db | >=19.1.0<19.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23375 is a remote code execution vulnerability in Microsoft ODBC and OLE DB.
CVE-2023-23375 has a severity rating of 7.8, which is considered high.
The affected software includes Microsoft OLE DB Driver 18 for SQL Server, Microsoft OLE DB Driver 19 for SQL Server, Microsoft ODBC Driver 18 for SQL Server, and Microsoft ODBC Driver 17 for SQL Server.
You can fix CVE-2023-23375 by applying the patches or updates provided by Microsoft for the affected software.
You can find more information about CVE-2023-23375 on the Microsoft Security Response Center (MSRC) website.