CVE-2024-21367: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21813Patch KB5034819 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22511Patch KB5034833 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26961Patch KB5034809 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24710Patch KB5034830 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6709Patch KB5034767 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20469Patch KB5034774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4046Patch KB5034763 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3155Patch KB5034765 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.709Patch KB5034769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4046Patch KB5034763 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3155Patch KB5034765 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2777Patch KB5034766 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5458Patch KB5034768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2322Patch KB5034770
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21367?
CVE-2024-21367 is rated as a critical vulnerability due to its potential for remote code execution in the Microsoft WDAC OLE DB provider.
How do I fix CVE-2024-21367?
To address CVE-2024-21367, you need to apply the latest security patches provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2024-21367?
CVE-2024-21367 affects specific versions of Windows 10, Windows 11, and Windows Server, such as 21H2 and 22H2.
What type of attacks can exploit CVE-2024-21367?
CVE-2024-21367 can be exploited through a specially crafted remote request that allows an attacker to execute arbitrary code.
Is CVE-2024-21367 being actively exploited?
As of the latest updates, there are indicators that CVE-2024-21367 is being actively exploited in the wild, making immediate patching crucial.