First published: Thu Jun 15 2023(Updated: )
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2019 | ||
Microsoft Visual Studio 2019 | =16.11 | |
Visual Studio Professional 2022 | =17.6 | |
Visual Studio Professional 2022 | =17.2 | |
Visual Studio Professional 2022 | =17.8 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.4.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.4.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.4.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.2.1.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.2.1.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.2.1.1 | |
Microsoft SQL Server | =2019 | |
Microsoft SQL Server | =2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32026 is a vulnerability in the Microsoft ODBC Driver for SQL Server that allows remote code execution.
CVE-2023-32026 has a severity rating of 7.8, which is considered high.
CVE-2023-32026 affects the Microsoft ODBC Driver 17 and 18 for SQL Server on Windows, MacOS, and Linux, as well as the SQL Server 2022 (CU 5) and 2019 (CU 21).
To fix CVE-2023-32026, you should apply the patches or updates provided by Microsoft for the affected ODBC drivers or SQL Server versions.
You can find more information about CVE-2023-32026 on the Microsoft Security Response Center website.