Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by tricking an un-authenticated user into attempting to connect to a malicious SQL server database via ODBC. This could result in the database returning malicious data that might cause arbitrary code execution on the client.
🎯 Affected products17
- Microsoft SQL Server 2008 R2 for 32-Bit Systems Service Pack 3 (QFE)
- Microsoft SQL Server 2008 R2 for x64-Based Systems Service Pack 3 (QFE)
- Microsoft SQL Server 2008 for 32-bit Systems Service Pack 4 (QFE)
- Microsoft SQL Server 2008 for x64-Based Systems Service Pack 4 (QFE)
- Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)
- Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)
- Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU 4)
- Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
- Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU 4)
- Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
- Microsoft SQL Server 2017 for x64-based Systems (CU 31)
- Microsoft SQL Server 2017 for x64-based Systems (GDR)
- Microsoft SQL Server 2019 for x64-based Systems (CU 18)
- Microsoft SQL Server 2019 for x64-based Systems (GDR)
- Microsoft SQL Server 2022 for x64-based Systems (GDR)
✅ Remediation
KB5021123 (Security Update) — fixed build 11.0.7512.11 KB5021127 (Security Update) — fixed build 14.0.2047.8 KB5021037 (Security Update) — fixed build 12.0.6444.4 KB5021045 (Security Update) — fixed build 12.0.6174.8 KB5021125 (Security Update) — fixed build 15.0.2101.7 KB5021129 (Security Update) — fixed build 13.0.6430.49 KB5021128 (Security Update) — fixed build 13.0.7024.30 KB5021126 (Security Update) — fixed build 14.0.3460.9 KB5021522 (Security Update) — fixed build 16.0.1050.5 KB5021124 (Security Update) — fixed build 15.0.4280.7 KB5021112 (Security Update) — fixed build 10.50.6785.2 KB5020863 (Security Update) — fixed build 10.0.6814.4
🔗 References (22)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21718
- referencehttps://support.microsoft.com/help/5021123
- patchhttps://www.microsoft.com/download/details.aspx?familyid=5521de5b-6966-4a1e-808d-93dd89c2240d
- referencehttps://support.microsoft.com/help/5021127
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ae1e0ab6-c49c-4ef2-a142-5cb531ef9235
- referencehttps://support.microsoft.com/help/5021037
- patchhttps://www.microsoft.com/download/details.aspx?familyid=d7dcf8ea-7219-48a1-941a-23460d9510df
- referencehttps://support.microsoft.com/help/5021045
- patchhttps://www.microsoft.com/download/details.aspx?familyid=9bedde5f-de1f-466b-bb67-d2a2d0dfc279
- referencehttps://support.microsoft.com/help/5021125
- patchhttps://www.microsoft.com/download/details.aspx?familyid=64412f99-8d5c-47bd-b89a-445b3fd5ce38
- referencehttps://support.microsoft.com/help/5021129
- patchhttps://www.microsoft.com/download/details.aspx?familyid=2b43cc11-e9d6-45ed-974b-ff7efb63699c
- referencehttps://support.microsoft.com/help/5021128
- patchhttps://www.microsoft.com/download/details.aspx?familyid=d2c2ddec-ab33-4dc5-b2ef-5a9f49d203c6
- referencehttps://support.microsoft.com/help/5021126
- patchhttps://www.microsoft.com/download/details.aspx?familyid=2f9ea572-d508-46b7-864f-882932c1ad37
- referencehttps://support.microsoft.com/help/5021522
- patchhttps://www.microsoft.com/download/details.aspx?familyid=32db4259-905f-4462-a2de-b0a0c4b5162b
- referencehttps://support.microsoft.com/help/5021124
- referencehttps://support.microsoft.com/help/5021112
- referencehttps://support.microsoft.com/help/5020863