First published: Tue Apr 09 2024(Updated: )
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2019 | ||
Microsoft Visual Studio 2019 | =16.11 | |
Visual Studio Professional 2022 | =17.6 | |
Visual Studio Professional 2022 | =17.9 | |
Microsoft SQL Server | ||
Microsoft SQL Server | ||
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.6.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.6.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.6.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.3.3.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.3.3.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.3.3.1 | |
Microsoft SQL Server | >=15.0.2000.5<15.0.2110.4 | |
Microsoft SQL Server | >=15.0.4003.23<15.0.4360.2 | |
Microsoft SQL Server | >=16.0.1000.6<16.0.1115.1 | |
Microsoft SQL Server | >=16.0.4003.1<16.0.4120.1 | |
Visual Studio Professional 2019 | >=16.0<16.11.35 | |
Visual Studio Professional 2022 | >=17.4.0<17.4.18 | |
Visual Studio Professional 2022 | >=17.6.0<17.6.14 | |
Visual Studio Professional 2022 | >=17.8.0<17.8.9 | |
Visual Studio Professional 2022 | >=17.9.0<17.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28932 has been rated as critical due to its potential for remote code execution.
To fix CVE-2024-28932, update the affected Microsoft software to the latest patched version.
CVE-2024-28932 affects multiple products including various versions of the Microsoft ODBC Driver for SQL Server, SQL Server 2019, SQL Server 2022, and Visual Studio 2019 and 2022.
There are no effective workarounds available for CVE-2024-28932; applying patches is strongly advised.
CVE-2024-28932 could be exploited through remote code execution attacks, enabling attackers to control affected systems.