CVE-2023-21681

CWE-1914 documents4 sources
Severity
8.8HIGH
EPSS
1.6%
top 18.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 11

Description

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages25 packages

CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.24075
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.5648
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.3887
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.1487
CVEListV5microsoft/windows_server_2012_r26.3.9600.06.3.9600.20778

🔴Vulnerability Details

2
GHSA
GHSA-xxrh-w3xc-mv6f: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability2023-01-11
CVEList
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability2023-01-10

📋Vendor Advisories

1
Microsoft
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability2023-01-10
CVE-2023-21681 (HIGH CVSS 8.8) | Microsoft WDAC OLE DB provider for | cvebase.io