CVE-2022-29143
published 2022-06-15CVE-2022-29143: Microsoft SQL Server Remote Code Execution Vulnerability
PriorityP350high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
1.97%
78.2th percentile
Microsoft SQL Server Remote Code Execution Vulnerability
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sql_server_2014_service_pack_3 | >= 12.0.0 < 12.0.6169.19 | 12.0.6169.19 |
| microsoft | microsoft_sql_server_2014_service_pack_3 | >= 12.0.0 < 12.0.6439.10 | 12.0.6439.10 |
| microsoft | microsoft_sql_server_2016_for_x64-based_systems_service_pack_2 | >= 13.0.0 < 13.0.5108.50 | 13.0.5108.50 |
| microsoft | microsoft_sql_server_2016_service_pack_2 | >= 13.0.0.0 < 13.0.5893.48 | 13.0.5893.48 |
| microsoft | microsoft_sql_server_2016_service_pack_3 | >= 13.0.0 < 13.0.6419.1 | 13.0.6419.1 |
| microsoft | microsoft_sql_server_2016_service_pack_3_azure_connect_feature_pack | >= 13.0.0 < 13.0.7016.1 | 13.0.7016.1 |
| microsoft | microsoft_sql_server_2017 | >= 14.0.0 < 14.0.2042.3 | 14.0.2042.3 |
| microsoft | microsoft_sql_server_2017 | >= 14.0.0.0 < 14.0.3445.2 | 14.0.3445.2 |
| microsoft | microsoft_sql_server_2019 | >= 15.0.0 < 15.0.2095.3 | 15.0.2095.3 |
| microsoft | microsoft_sql_server_2019 | >= 15.0.0.0 < 15.0.4236.7 | 15.0.4236.7 |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| msrc | microsoft_sql_server_2014_service_pack_3_for_32-bit_systems | — | — |
| msrc | microsoft_sql_server_2014_service_pack_3_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_2 | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_3 | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_3_azure_connect_fea | — | — |
| msrc | microsoft_sql_server_2017_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2019_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f4rw-r75j-wr7m: Microsoft SQL Server Remote Code Execution Vulnerability
ghsa_unreviewed·2022-06-16
CVE-2022-29143 [HIGH] GHSA-f4rw-r75j-wr7m: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability.
Microsoft
Microsoft SQL Server Remote Code Execution Vulnerability
vendor_msrc·2022-06-14·CVSS 7.5
CVE-2022-29143 [HIGH] Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated attacker could exploit the vulnerability by executing a specially crafted query using $ partition against a table with a Column Store index.
FAQ: There are GDR and/or CU (Cumulative Update) updates offered for my version of SQL Server. How do I know which update to use?
First, determine your SQL Server version number. For more information on determining your SQL Server version number, see Microsoft Knowledge Base Article 321185 - How to determine the version, edition, and update level of SQL Server and its components.
Second, in the table below, locate your version number or the version range that your version number falls within. The corresponding update is t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-15
Published