CVE-2023-38169: Microsoft SQL OLE DB Remote Code Execution Vulnerability
Microsoft OLE DB Remote Code Execution Vulnerability
Other sources
Microsoft SQL OLE DB Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.10.4.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.3.0001.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.2.1.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.2.2.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4316.3Patch KB5025808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.6.0006.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4053.3Patch KB5026806
Event History
Frequently Asked Questions
What is CVE-2023-38169?
CVE-2023-38169 is a Microsoft OLE DB Remote Code Execution Vulnerability that affects various versions of Microsoft SQL Server and OLE DB drivers.
How severe is CVE-2023-38169?
CVE-2023-38169 has a severity rating of 8.8, which is considered high.
Which software is affected by CVE-2023-38169?
Various versions of Microsoft SQL Server and OLE DB drivers are affected by CVE-2023-38169.
How can I fix CVE-2023-38169?
To fix CVE-2023-38169, apply the relevant patches or updates provided by Microsoft for the affected software versions.
Where can I find more information about CVE-2023-38169?
You can find more information about CVE-2023-38169 on the Microsoft Security Response Center website.