CVE-2023-28304: Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Published Apr 11, 2023
·Updated
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Affected Software
10 affected componentsFixes available
Microsoft OLE DB Driver 18 for SQL Server
Microsoft OLE DB Driver 19 for SQL Server
Microsoft ODBC Driver 17 for SQL Server
Microsoft OLE DB Driver 18 for SQL Server
Microsoft Odbc Sql Server>=17.0<17.10.3.1
Microsoft Odbc Sql Server>=18.0<18.2.1.1
Microsoft Ole Db Sql Server>=18.0<18.6.5
Microsoft Ole Db Sql Server>=19.1.0<19.3.0
Microsoft ODBC Driver 18 for SQL Server
Microsoft ODBC Driver 18 for SQL Server
Remediation
Event History
Apr 11, 2023
CVE Published
07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-28304?
CVE-2023-28304 is a Microsoft ODBC and OLE DB Remote Code Execution Vulnerability.
2
How severe is CVE-2023-28304?
CVE-2023-28304 has a severity rating of 7.8 (high).
3
Which software is affected by CVE-2023-28304?
The software affected by CVE-2023-28304 includes Microsoft OLE DB Driver 18 for SQL Server, Microsoft OLE DB Driver 19 for SQL Server, Microsoft ODBC Driver 18 for SQL Server, and Microsoft ODBC Driver 17 for SQL Server.
4
How can I fix CVE-2023-28304?
To fix CVE-2023-28304, you should download and apply the patches provided by Microsoft for the affected software.
5
Where can I find more information about CVE-2023-28304?
You can find more information about CVE-2023-28304 on the Microsoft Security Response Center website.