CVE-2023-21718HighCVSS 7.8

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

Published
February 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by tricking an un-authenticated user into attempting to connect to a malicious SQL server database via ODBC. This could result in the database returning malicious data that might cause arbitrary code execution on the client.

🎯 Affected products17

  • Microsoft SQL Server 2008 R2 for 32-Bit Systems Service Pack 3 (QFE)
  • Microsoft SQL Server 2008 R2 for x64-Based Systems Service Pack 3 (QFE)
  • Microsoft SQL Server 2008 for 32-bit Systems Service Pack 4 (QFE)
  • Microsoft SQL Server 2008 for x64-Based Systems Service Pack 4 (QFE)
  • Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE)
  • Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)
  • Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU 4)
  • Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
  • Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU 4)
  • Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)
  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
  • Microsoft SQL Server 2017 for x64-based Systems (CU 31)
  • Microsoft SQL Server 2017 for x64-based Systems (GDR)
  • Microsoft SQL Server 2019 for x64-based Systems (CU 18)
  • Microsoft SQL Server 2019 for x64-based Systems (GDR)
  • Microsoft SQL Server 2022 for x64-based Systems (GDR)

✅ Remediation

KB5021123 (Security Update) — fixed build 11.0.7512.11 KB5021127 (Security Update) — fixed build 14.0.2047.8 KB5021037 (Security Update) — fixed build 12.0.6444.4 KB5021045 (Security Update) — fixed build 12.0.6174.8 KB5021125 (Security Update) — fixed build 15.0.2101.7 KB5021129 (Security Update) — fixed build 13.0.6430.49 KB5021128 (Security Update) — fixed build 13.0.7024.30 KB5021126 (Security Update) — fixed build 14.0.3460.9 KB5021522 (Security Update) — fixed build 16.0.1050.5 KB5021124 (Security Update) — fixed build 15.0.4280.7 KB5021112 (Security Update) — fixed build 10.50.6785.2 KB5020863 (Security Update) — fixed build 10.0.6814.4

🔗 References (22)