CVE-2024-37965: Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4390.2Patch KB5042749 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2120.1Patch KB5042214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1125.1Patch KB5042211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3475.1Patch KB5042215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4140.3Patch KB5042578 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2060.1Patch KB5042217 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7040.1Patch KB5042209 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6445.1Patch KB5042207
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37965?
CVE-2024-37965 is classified as an Elevation of Privilege vulnerability in Microsoft SQL Server.
How do I fix CVE-2024-37965?
To fix CVE-2024-37965, apply the latest security patches provided by Microsoft for the affected versions of SQL Server.
Which products are affected by CVE-2024-37965?
CVE-2024-37965 affects Microsoft SQL Server 2016, 2017, 2019, and 2022 across several update levels.
What versions of SQL Server are vulnerable to CVE-2024-37965?
Vulnerable versions include SQL Server 2016 SP3, SQL Server 2017 (CU 31), SQL Server 2019 (up to CU 28), and SQL Server 2022.
What are the potential impacts of exploiting CVE-2024-37965?
Exploiting CVE-2024-37965 could allow an attacker to gain elevated privileges, potentially compromising database security.