CVE-2023-36417: Microsoft SQL OLE DB Remote Code Execution Vulnerability
Microsoft SQL OLE DB Remote Code Execution Vulnerability
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-36417?
CVE-2023-36417 is a vulnerability in Microsoft SQL ODBC Driver that allows remote code execution.
How severe is CVE-2023-36417?
CVE-2023-36417 has a severity of 7.8, which is considered high.
What software is affected by CVE-2023-36417?
The affected software includes Microsoft SQL Server 2022, Microsoft OLE DB Driver 18 for SQL Server, Microsoft OLE DB Driver 19 for SQL Server, and Microsoft SQL Server 2019.
How do I fix CVE-2023-36417 in Microsoft SQL Server 2022?
To fix CVE-2023-36417 in Microsoft SQL Server 2022, you can apply the patch available at https://www.microsoft.com/download/details.aspx?familyid=59387692-a103-47b7-aae0-96a679fdd2e6.
How do I fix CVE-2023-36417 in Microsoft SQL Server 2019?
To fix CVE-2023-36417 in Microsoft SQL Server 2019, you can apply the patch available at https://www.microsoft.com/download/details.aspx?familyid=4ad4dd87-9e09-4848-92b0-4c06058a8fcf.