cbcvebase.
CVE-2022-38040
published 2022-10-11

CVE-2022-38040: Microsoft ODBC Driver Remote Code Execution Vulnerability

PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.48%
70.9th percentile
Microsoft ODBC Driver Remote Code Execution Vulnerability

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1950710.0.10240.19507
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.542710.0.14393.5427
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.353210.0.17763.3532
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.353210.0.17763.3532
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.213010.0.19042.2130
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.213010.0.19043.2130
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.213010.0.19044.2130
microsoftwindows_11
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.109810.0.22000.1098
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.67410.0.22621.674
microsoftwindows_7>= 6.1.0 < 6.1.7601.261746.1.7601.26174
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.261746.1.7601.26174
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.206256.3.9600.20625
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.261746.1.7601.26174
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.217216.0.6003.21721
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.239206.2.9200.23920
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.206256.3.9600.20625
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.542710.0.14393.5427

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to initiate an ODBC connection to an attacker-controlled SQL server; monitor for outbound ODBC/TDS connections (default TCP 1433) to unknown or external hosts initiated by end-user processes.
  • The exploit is client-side RCE triggered by a malicious networking packet from a rogue SQL server; alert on unexpected child processes spawned by ODBC-consuming applications (e.g., Excel, Access, custom apps) after an outbound SQL connection.
  • Social-engineering / phishing is the likely delivery mechanism; monitor for user-initiated ODBC DSN changes or connection-string files (.dsn, .udl) pointing to external IPs/domains.
  • ·Exploitation is rated 'Less Likely' for both latest and older software releases; no public exploit or in-the-wild exploitation confirmed at time of advisory.
  • ·Customer action is required; patching alone is insufficient without ensuring end-users cannot be socially engineered into connecting to untrusted SQL servers.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.