CVE-2024-49018HighCVSS 8.8
SQL Server Native Client Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by tricking an authenticated user (UI:R) into attempting to connect to a malicious SQL server database via a connection driver (for example: OLE DB or OLEDB as applicable). This could result in the database returning malicious data that could cause arbitrary code execution on the client.
🎯 Affected products6
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
- Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
- Microsoft SQL Server 2017 for x64-based Systems (CU 31)
- Microsoft SQL Server 2017 for x64-based Systems (GDR)
- Microsoft SQL Server 2019 for x64-based Systems (CU 29)
- Microsoft SQL Server 2019 for x64-based Systems (GDR)
✅ Remediation
KB5046857 (Security Update) — fixed build 14.0.2070.1 KB5046859 (Security Update) — fixed build 15.0.2130.3 KB5046855 (Security Update) — fixed build 13.0.6455.2 KB5046856 (Security Update) — fixed build 13.0.7050.2 KB5046858 (Security Update) — fixed build 14.0.3485.1 KB5046860 (Security Update) — fixed build 15.0.4410.1
🔗 References (13)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49018
- patchhttps://www.microsoft.com/download/details.aspx?familyid=09e83a7b-42e4-4eed-b9a9-47e677391102
- referencehttps://support.microsoft.com/help/5046857
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7744f829-703a-4937-a38e-f07daa6611bc
- referencehttps://support.microsoft.com/help/5046859
- patchhttps://www.microsoft.com/download/details.aspx?familyid=bdefbc71-f4ac-4adf-8fc3-5ab090847240
- referencehttps://support.microsoft.com/help/5046855
- patchhttps://www.microsoft.com/download/details.aspx?familyid=2a4f8082-3468-4c6b-9d5f-2a56ef9590aa
- referencehttps://support.microsoft.com/help/5046856
- patchhttps://www.microsoft.com/download/details.aspx?familyid=6f62546d-da84-4965-89db-190d7ba41f42
- referencehttps://support.microsoft.com/help/5046858
- patchhttps://www.microsoft.com/download/details.aspx?familyid=d7ab6ee0-bcf2-4b55-8d9d-ffe7976a4a03
- referencehttps://support.microsoft.com/help/5046860