CVE-2024-37339: Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Published Sep 10, 2024
·Updated
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Affected Software
14 affected componentsFixes available
Microsoft Sql 2016 Azure Connect Feature Pack>=13.0.7000.253<=13.0.7037.1
Microsoft SQL Server 2016>=13.0.6300.2<13.0.6441.1
Microsoft SQL Server 2017>=14.0.1000.169<14.0.2060.1
Microsoft SQL Server 2017>=14.0.3006.16<14.0.3475.1
Microsoft SQL Server 2019>=15.0.2000.5<15.0.2120.1
Microsoft SQL Server 2019>=15.0.4003.23<15.0.4390.2
Microsoft SQL Server 2022>=16.0.1000.6<16.0.1125.1
Microsoft SQL Server 2022>=16.0.4003.1<16.0.4140.3
Microsoft SQL Server 2017<14.0.2060.1
14.0.2060.1
Microsoft SQL Server 2022 (CU 14)<16.0.4140.3
16.0.4140.3
Microsoft SQL Server 2017 (CU 31)<14.0.3475.1
14.0.3475.1
Microsoft SQL Server 2019<15.0.2120.1
15.0.2120.1
Microsoft SQL Server 2019 (CU 28)<15.0.4390.2
15.0.4390.2
Microsoft SQL Server 2022<16.0.1125.1
16.0.1125.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2060.1Patch KB5042217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4140.3Patch KB5042578 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3475.1Patch KB5042215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2120.1Patch KB5042214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4390.2Patch KB5042749 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1125.1Patch KB5042211
Event History
Sep 10, 2024
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Are there any mitigation strategies for CVE-2024-37339?
While patching is the primary solution for CVE-2024-37339, users can also limit SQL Server exposure by implementing network security controls.