CVE-2023-38151HighCVSS 8.8

Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability

Published
November 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target machine if the victim connects to the attacker's malicious DB2 server and they execute a specially crafted query.

🎯 Affected products2

  • Host Integration Server 2020
  • Microsoft OLE DB Provider for DB2 V7

✅ Remediation

KB5032921 (Security Update) — fixed build KB5032921

🔗 References (2)