First published: Thu Jun 15 2023(Updated: )
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server 2019 (CU 21) | ||
Microsoft SQL Server 2022 (CU 5) | ||
Microsoft ODBC Driver 18 for SQL Server on MacOS | ||
Microsoft OLE DB Driver 19 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server on Windows | ||
Microsoft ODBC Driver 17 for SQL Server on MacOS | ||
Microsoft ODBC Driver 17 for SQL Server on Linux | ||
Microsoft ODBC Driver 17 for SQL Server on Windows | ||
Microsoft Visual Studio 2019 (includes 16.0 - 16.10) | =16.11 | |
Microsoft OLE DB Driver 18 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server on Linux | ||
Microsoft Visual Studio 2022 | =17.6 | |
Microsoft Visual Studio 2022 | =17.2 | |
Microsoft Visual Studio 2022 | =17.8 | |
Microsoft Odbc Driver For Sql Server | >=17.0.1.1<17.10.4.1 | |
Microsoft Odbc Driver For Sql Server | >=17.0.1.1<17.10.4.1 | |
Microsoft Odbc Driver For Sql Server | >=17.0.1.1<17.10.4.1 | |
Microsoft Odbc Driver For Sql Server | >=18.0.1.1<18.2.1.1 | |
Microsoft Odbc Driver For Sql Server | >=18.0.1.1<18.2.1.1 | |
Microsoft Odbc Driver For Sql Server | >=18.0.1.1<18.2.1.1 | |
Microsoft OLE DB Driver for SQL Server | >=18.0.2<18.6.0006.0 | |
Microsoft OLE DB Driver for SQL Server | >=19.0.0<19.3.0001.0 | |
Microsoft SQL Server | =2019 | |
Microsoft SQL Server | =2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29349 is a remote code execution vulnerability in Microsoft ODBC and OLE DB.
CVE-2023-29349 allows remote attackers to execute arbitrary code on systems where vulnerable versions of Microsoft ODBC and OLE DB are installed.
CVE-2023-29349 affects several software products, including ODBC Driver 18 and 17 for SQL Server on Windows, Linux, and macOS, OLE DB Driver 18 and 19 for SQL Server, and SQL Server 2022 (CU 5) and 2019 (CU 21).
CVE-2023-29349 has a severity rating of 7.8, which is considered as high severity.
To fix CVE-2023-29349, update your Microsoft ODBC and OLE DB software to the latest version provided by Microsoft.