First published: Tue Jul 09 2024(Updated: )
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server 2019 for Linux Containers | ||
Microsoft SQL Server 2017 | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2016 Azure Connect Feature Pack | ||
Microsoft SQL Server | ||
Microsoft SQL Server 2016 T-SQL Language Service | ||
Microsoft SQL Server 2016 T-SQL Language Service | >=13.0.6300.2<13.0.6441.1 | |
Microsoft SQL Server 2016 T-SQL Language Service | >=13.0.7000.253<13.0.7037.1 | |
Microsoft SQL Server | >=14.0.1000.169<14.0.2056.2 | |
Microsoft SQL Server | >=14.0.3006.16<14.0.3471.2 | |
Microsoft SQL Server | >=15.0.2000.5<15.0.2116.2 | |
Microsoft SQL Server | >=15.0.4003.23<15.0.4382.1 | |
Microsoft SQL Server | >=16.0.1000.6<16.0.1121.4 | |
Microsoft SQL Server | >=16.0.4003.1<16.0.4131.2 | |
Microsoft SQL Server | ||
Microsoft SQL Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21332 has been assigned a high severity rating due to its potential for remote code execution.
To fix CVE-2024-21332, apply the latest security patches provided by Microsoft for the affected SQL Server versions.
CVE-2024-21332 affects SQL Server 2016, 2017, 2019, and 2022 across multiple cumulative updates and service packs.
CVE-2024-21332 is a remote code execution vulnerability found in the SQL Server Native Client OLE DB Provider.
In addition to applying patches, ensure that least privilege principles are followed and unused services are disabled to mitigate the impact of CVE-2024-21332.