CVE-2024-37966: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4390.2Patch KB5042749 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4140.3Patch KB5042578 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3475.1Patch KB5042215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2120.1Patch KB5042214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1125.1Patch KB5042211 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2060.1Patch KB5042217
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37966?
The severity of CVE-2024-37966 is rated as high due to the potential for information disclosure.
How do I fix CVE-2024-37966?
To fix CVE-2024-37966, apply the latest patches provided by Microsoft for your SQL Server version.
Which Microsoft SQL Server versions are affected by CVE-2024-37966?
CVE-2024-37966 affects multiple versions including SQL Server 2017, 2019, and 2022.
What is the nature of the vulnerability in CVE-2024-37966?
CVE-2024-37966 is an information disclosure vulnerability in Microsoft SQL Server Native Scoring.
Can CVE-2024-37966 be exploited remotely?
Yes, CVE-2024-37966 has the potential to be exploited remotely if the conditions are met.