First published: Tue Mar 12 2024(Updated: )
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows 10 | =1809 | |
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server 2022 23H2 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows 10 | <10.0.10240.20596 | |
Microsoft Windows 10 | <10.0.14393.6897 | |
Microsoft Windows 10 | <10.0.17763.5696 | |
Microsoft Windows 10 | <10.0.19044.4291 | |
Microsoft Windows 10 22H2 | <10.0.19045.4291 | |
Windows 11 | <10.0.22000.2899 | |
Windows 11 | <10.0.22621.3447 | |
Windows 11 | <10.0.22631.3447 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | <10.0.14393.6897 | |
Microsoft Windows Server 2019 | <10.0.17763.5696 | |
Microsoft Windows Server 2022 | <10.0.20348.2402 | |
Microsoft Windows Server 2022 | <10.0.25398.830 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2019 | ||
Windows 11 | =23H2 | |
Windows 11 | =22H2 | |
Windows 11 | =22H2 | |
Windows 11 | =21H2 | |
Windows 11 | =21H2 | |
Windows 11 | =23H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21450 is classified as a remote code execution vulnerability in the Microsoft WDAC OLE DB provider for SQL Server.
To fix CVE-2024-21450, apply the relevant patches provided by Microsoft for your affected version and product.
CVE-2024-21450 affects multiple Microsoft products including Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022.
Yes, CVE-2024-21450 allows an attacker to execute arbitrary code remotely on vulnerable systems.
Currently, the best practice is to apply the available security updates as the vulnerability can be exploited without any known workarounds.