First published: Tue Jul 09 2024(Updated: )
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server 2019 for Linux Containers | ||
Microsoft SQL Server 2017 | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2016 Azure Connect Feature Pack | ||
Microsoft SQL Server | ||
Microsoft SQL Server | ||
Microsoft SQL Server 2016 (CU 17) | ||
Microsoft SQL Server 2016 (CU 17) | <13.0.6441.1 | |
Microsoft SQL Server 2016 (CU 17) | >=13.0.7000.253<13.0.7037.1 | |
Microsoft SQL Server | <14.0.2056.2 | |
Microsoft SQL Server | >=14.0.3456.2<14.0.3471.2 | |
Microsoft SQL Server | <15.0.2116.2 | |
Microsoft SQL Server | >=15.0.4375.4<15.0.4382.1 | |
Microsoft SQL Server | <16.0.1121.4 | |
Microsoft SQL Server | >=16.0.4125.3<16.0.4131.2 | |
Microsoft SQL Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38088 has been assigned a high severity rating due to its potential for remote code execution.
To fix CVE-2024-38088, apply the latest security patches released by Microsoft for your version of SQL Server.
CVE-2024-38088 affects Microsoft SQL Server 2016, 2017, 2019, and 2022, as detailed in the vulnerability report.
CVE-2024-38088 is classified as a Remote Code Execution vulnerability within the SQL Server Native Client OLE DB Provider.
While applying patches is the most effective solution, reducing network exposure and restricting access can help mitigate risks associated with CVE-2024-38088.