First published: Tue Nov 12 2024(Updated: )
SQL Server Native Client Remote Code Execution Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server 2017 | ||
Microsoft SQL Server 2016 Azure Connect Feature Pack | ||
Microsoft SQL Server 2019 | ||
Microsoft SQL Server | ||
Microsoft SQL Server 2016 (CU 17) | ||
Microsoft SQL Server 2016 (CU 17) | >=13.0.6300.2<13.0.6455.2 | |
Microsoft SQL Server 2016 (CU 17) | >=13.0.7000.253<13.0.7050.2 | |
Microsoft SQL Server | >=14.0.1000.169<14.0.2070.1 | |
Microsoft SQL Server | >=14.0.3006.16<14.0.3485.1 | |
Microsoft SQL Server | >=15.0.2000.5<15.0.2130.3 | |
Microsoft SQL Server | >=15.0.4003.23<15.0.4410.1 | |
Microsoft SQL Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48995 is a remote code execution vulnerability affecting SQL Server Native Client.
To fix CVE-2024-48995, you should apply the latest security patches provided by Microsoft for the affected SQL Server versions.
CVE-2024-48995 affects SQL Server 2016, SQL Server 2017, and SQL Server 2019 across various update levels.
Yes, CVE-2024-48995 allows attackers to execute arbitrary code remotely through the SQL Server Native Client.
You should restrict access to your SQL Server instances and ensure that all security patches are applied promptly to mitigate CVE-2024-48995.