CVE-2024-37341: Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4150.1Patch KB5046059 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4395.2Patch KB5046060 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1130.5Patch KB5046057 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2125.1Patch KB5046056 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3480.1Patch KB5046061 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6450.1Patch KB5046063 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2065.1Patch KB5046058 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7045.2Patch KB5046062
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37341?
CVE-2024-37341 is classified as an elevation of privilege vulnerability.
How do I fix CVE-2024-37341?
To fix CVE-2024-37341, apply the latest security updates and patches provided by Microsoft for the affected SQL Server versions.
Which Microsoft SQL Server versions are affected by CVE-2024-37341?
CVE-2024-37341 affects Microsoft SQL Server 2016, 2017, 2019, and 2022 across various cumulative updates.
What potential risks does CVE-2024-37341 pose?
CVE-2024-37341 could allow an attacker to elevate their privileges on vulnerable SQL Server instances.
Are there any patch requirements for CVE-2024-37341?
Yes, applying the relevant security updates as specified in the Microsoft guidance is required to mitigate CVE-2024-37341.