First published: Tue Oct 10 2023(Updated: )
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ODBC Driver 18 for SQL Server on Windows | ||
Microsoft ODBC Driver 18 for SQL Server on MacOS | ||
Microsoft SQL Server 2022 (CU 8) | ||
Microsoft ODBC Driver 17 for SQL Server on MacOS | ||
Microsoft ODBC Driver 17 for SQL Server on Linux | ||
Microsoft ODBC Driver 18 for SQL Server on Linux | ||
Microsoft ODBC Driver 17 for SQL Server on Windows | ||
Microsoft SQL Server 2019 (CU 22) | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2019 | ||
Microsoft ODBC Driver 18 for SQL Server on Windows | >=17<17.10.5.1 | |
Microsoft ODBC Driver 18 for SQL Server on MacOS | >=17<17.10.5.1 | |
Microsoft SQL Server 2022 (CU 5) | >=17.0.1.1<17.10.5.1 | |
Microsoft ODBC Driver 18 for SQL Server on Windows | >=18.0<18.3.2.1 | |
Microsoft ODBC Driver 18 for SQL Server on MacOS | >=18.0<18.3.2.1 | |
Microsoft SQL Server 2022 (CU 5) | >=18.0.1.1<18.3.2.1 | |
Microsoft SQL Server | =2019 | |
Microsoft SQL Server | =2022 | |
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2019 (CU 22) | ||
Microsoft SQL Server 2019 | ||
Microsoft SQL Server 2022 (CU 8) | ||
Microsoft Odbc Driver For Sql Server | >=17<17.10.5.1 | |
Microsoft Odbc Driver For Sql Server | >=17<17.10.5.1 | |
Microsoft Odbc Driver For Sql Server | >=17.0.1.1<17.10.5.1 | |
Microsoft Odbc Driver For Sql Server | >=18.0<18.3.2.1 | |
Microsoft Odbc Driver For Sql Server | >=18.0<18.3.2.1 | |
Microsoft Odbc Driver For Sql Server | >=18.0.1.1<18.3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36420 is a vulnerability in Microsoft ODBC Driver for SQL Server that allows remote code execution.
The Microsoft ODBC Driver 17 and 18 for SQL Server on MacOS, Linux, and Windows, as well as Microsoft SQL Server 2019 and 2022, are affected.
CVE-2023-36420 has a severity score of 7.3, which is considered high.
You can fix CVE-2023-36420 for Microsoft ODBC Driver 17 for SQL Server on MacOS by following the provided remedy URL or installing the patch from the provided download URL.
You can fix CVE-2023-36420 for Microsoft SQL Server 2022 by following the provided remedy URL or installing the patch from the provided download URL.