CVE-2024-21353: Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability
Published Feb 13, 2024
·Updated
Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability
Affected Software
2 affected componentsFixes available
Microsoft Windows Server 2022 23h2<10.0.25398.709
Microsoft Windows Server 2022, 23H2 Edition<10.0.25398.709
10.0.25398.709
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.709Patch KB5034769
Event History
Feb 13, 2024
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21353?
CVE-2024-21353 has been rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2024-21353?
To fix CVE-2024-21353, apply the latest security update from Microsoft KB5034769.
3
Which versions of Windows are affected by CVE-2024-21353?
CVE-2024-21353 affects Microsoft Windows Server 2022 23H2 up to version 10.0.25398.709.
4
What type of vulnerability is CVE-2024-21353?
CVE-2024-21353 is classified as a remote code execution vulnerability in the Microsoft WDAC ODBC Driver.
5
Who is the vendor for CVE-2024-21353?
The vendor for CVE-2024-21353 is Microsoft.