CVE-2024-29047: Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Published Apr 9, 2024
·Updated
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Affected Software
4 affected componentsFixes available
Microsoft SQL Server 2022 (CU 12)
Microsoft SQL Server 2019 (CU 25)
Microsoft SQL Server 2019>=15.0.4003.23<15.0.4360.2
Microsoft SQL Server 2022>=16.0.4003.1<16.0.4120.1
Event History
Apr 9, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29047?
CVE-2024-29047 has been identified as a critical vulnerability that allows remote code execution in Microsoft SQL Server.
2
How do I fix CVE-2024-29047?
To fix CVE-2024-29047, you should apply the latest cumulative updates for Microsoft SQL Server 2019 or 2022.
3
Which versions of SQL Server are affected by CVE-2024-29047?
CVE-2024-29047 affects Microsoft SQL Server 2019 (CU 25) and SQL Server 2022 (CU 12).
4
Can CVE-2024-29047 lead to data breaches?
Yes, CVE-2024-29047 could potentially allow attackers to execute arbitrary code, leading to unauthorized access and data breaches.
5
Is there a patch available for CVE-2024-29047?
Yes, Microsoft has released patches for CVE-2024-29047 which should be applied immediately to affected systems.