CVE-2024-28911: Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Published Apr 9, 2024
·Updated
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Affected Software
12 affected componentsFixes available
Microsoft OLE DB Driver 18 for SQL Server
Microsoft OLE DB Driver 19 for SQL Server
Microsoft SQL Server 2022 (CU 12)
Microsoft SQL Server 2019 (CU 25)
Microsoft SQL Server 2022
Microsoft SQL Server 2019
Microsoft OLE DB Driver for SQL Server>=18.0.2<18.7.0002.0
Microsoft OLE DB Driver for SQL Server>=19.0.0<19.3.0003.0
Microsoft SQL Server 2019>=15.0.2000.5<15.0.2110.4
Microsoft SQL Server 2019>=15.0.4003.23<15.0.4360.2
Microsoft SQL Server 2022>=16.0.1000.6<16.0.1115.1
Microsoft SQL Server 2022>=16.0.4003.1<16.0.4120.1
Event History
Apr 9, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28911?
CVE-2024-28911 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-28911?
To mitigate CVE-2024-28911, update to the latest version of affected Microsoft OLE DB Driver or SQL Server as detailed in the official patches.
3
Which versions are affected by CVE-2024-28911?
CVE-2024-28911 affects Microsoft OLE DB Driver 18, OLE DB Driver 19, SQL Server 2019, and SQL Server 2022 across specific version ranges.
4
What types of attacks can exploit CVE-2024-28911?
CVE-2024-28911 can be exploited for remote code execution attacks, allowing attackers to run arbitrary code on the target system.
5
Is there a workaround for CVE-2024-28911?
Currently, the best approach against CVE-2024-28911 is to apply the recommended patches from Microsoft, as there are no confirmed effective workarounds.