CVE-2024-49018HighCVSS 8.8

SQL Server Native Client Remote Code Execution Vulnerability

Published
November 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by tricking an authenticated user (UI:R) into attempting to connect to a malicious SQL server database via a connection driver (for example: OLE DB or OLEDB as applicable). This could result in the database returning malicious data that could cause arbitrary code execution on the client.

🎯 Affected products6

  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
  • Microsoft SQL Server 2017 for x64-based Systems (CU 31)
  • Microsoft SQL Server 2017 for x64-based Systems (GDR)
  • Microsoft SQL Server 2019 for x64-based Systems (CU 29)
  • Microsoft SQL Server 2019 for x64-based Systems (GDR)

✅ Remediation

KB5046857 (Security Update) — fixed build 14.0.2070.1 KB5046859 (Security Update) — fixed build 15.0.2130.3 KB5046855 (Security Update) — fixed build 13.0.6455.2 KB5046856 (Security Update) — fixed build 13.0.7050.2 KB5046858 (Security Update) — fixed build 14.0.3485.1 KB5046860 (Security Update) — fixed build 15.0.4410.1

🔗 References (13)