First published: Tue Apr 09 2024(Updated: )
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 17 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft ODBC Driver 18 for SQL Server | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2019 | ||
Microsoft Visual Studio 2019 | =16.11 | |
Visual Studio Professional 2022 | =17.9 | |
Visual Studio Professional 2022 | =17.6 | |
Microsoft SQL Server | ||
Microsoft SQL Server | ||
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.6.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.6.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=17.0.1.1<17.10.6.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.3.3.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.3.3.1 | |
Microsoft ODBC Driver 13 for SQL Server | >=18.0.1.1<18.3.3.1 | |
Microsoft SQL Server | >=15.0.2000.5<15.0.2110.4 | |
Microsoft SQL Server | >=15.0.4003.23<15.0.4360.2 | |
Microsoft SQL Server | >=16.0.1000.6<16.0.1115.1 | |
Microsoft SQL Server | >=16.0.4003.1<16.0.4120.1 | |
Visual Studio Professional 2019 | >=16.0<16.11.35 | |
Visual Studio Professional 2022 | >=17.4.0<17.4.18 | |
Visual Studio Professional 2022 | >=17.6.0<17.6.14 | |
Visual Studio Professional 2022 | >=17.8.0<17.8.9 | |
Visual Studio Professional 2022 | >=17.9.0<17.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28936 is classified as a Remote Code Execution vulnerability, which poses a significant risk to affected systems.
To remedy CVE-2024-28936, users should apply the latest patches available for the affected Microsoft ODBC Driver and Visual Studio versions.
CVE-2024-28936 affects the Microsoft ODBC Driver 17 and 18 for SQL Server, as well as several versions of Visual Studio 2022 and SQL Server 2019 and 2022.
Currently, the recommended approach for CVE-2024-28936 is to apply available patches rather than relying on workarounds.
Failing to address CVE-2024-28936 could lead to unauthorized remote code execution by attackers, compromising system security.