CVE-2024-37340: Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3475.1Patch KB5042215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1125.1Patch KB5042211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4390.2Patch KB5042749 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4140.3Patch KB5042578 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2060.1Patch KB5042217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2120.1Patch KB5042214
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37340?
CVE-2024-37340 has been classified with a high severity rating due to its potential for remote code execution.
How do I fix CVE-2024-37340?
To fix CVE-2024-37340, apply the recommended patches provided by Microsoft for the affected SQL Server versions.
Which products are affected by CVE-2024-37340?
CVE-2024-37340 affects Microsoft SQL Server 2016, 2017, 2019, and 2022 across various updates and configurations.
What types of vulnerabilities does CVE-2024-37340 introduce?
CVE-2024-37340 introduces remote code execution vulnerabilities which could allow an attacker to execute arbitrary code on the affected system.
Is there a way to mitigate CVE-2024-37340 without applying patches?
While the best mitigation is applying patches, limiting network access to the SQL Server instances can reduce exposure to CVE-2024-37340.