CVE-2023-21718
published 2023-02-14CVE-2023-21718: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.74%
50.5th percentile
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sql_server_2008_r2_service_pack_3 | >= 10.0.0 < 10.50.6785.2 | 10.50.6785.2 |
| microsoft | microsoft_sql_server_2008_service_pack_4 | >= 10.0.0 < 10.0.6814.4 | 10.0.6814.4 |
| microsoft | microsoft_sql_server_2012_for_x64-based_systems_service_pack_4 | >= 11.0.0 < 11.0.7512.11 | 11.0.7512.11 |
| microsoft | microsoft_sql_server_2012_service_pack_4 | >= 11.0.0 < 11.0.7512.11 | 11.0.7512.11 |
| microsoft | microsoft_sql_server_2014_service_pack_3 | >= 12.0.0 < 12.0.6444.4 | 12.0.6444.4 |
| microsoft | microsoft_sql_server_2014_service_pack_3 | >= 12.0.0 < 12.0.6174.8 | 12.0.6174.8 |
| microsoft | microsoft_sql_server_2016_service_pack_3 | >= 13.0.0 < 13.0.6430.49 | 13.0.6430.49 |
| microsoft | microsoft_sql_server_2016_service_pack_3_azure_connect_feature_pack | >= 13.0.0 < 13.0.7024.30 | 13.0.7024.30 |
| microsoft | microsoft_sql_server_2017 | >= 14.0.0 < 14.0.2047.8 | 14.0.2047.8 |
| microsoft | microsoft_sql_server_2017 | >= 14.0.0 < 14.0.3460.9 | 14.0.3460.9 |
| microsoft | microsoft_sql_server_2019 | >= 15.0.0 < 15.0.2101.7 | 15.0.2101.7 |
| microsoft | microsoft_sql_server_2019 | >= 15.0.0 < 15.0.4280.7 | 15.0.4280.7 |
| microsoft | microsoft_sql_server_2022 | >= 16.0.0 < 16.0.1050.5 | 16.0.1050.5 |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| msrc | microsoft_odbc_driver_17_for_sql_server | — | — |
| msrc | microsoft_odbc_driver_18_for_sql_server | — | — |
| msrc | microsoft_ole_db_driver_18_for_sql_server | — | — |
| msrc | microsoft_ole_db_driver_19_for_sql_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Telecontrol Server Basic
cisa_ics·2024-04-11
Siemens Telecontrol Server Basic
ICS Advisory
##
Siemens Telecontrol Server Basic
Release DateApril 11, 2024
Alert CodeICSA-24-102-08
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Telecontrol Server Basic
- Vulnerabilities: Inadequate Encryption Strength, Double Free, Integer Overflow or Wraparound, External Control of File Name or Path, Path Traversal, Improper Input Validation, Missing Encry
Microsoft
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
vendor_msrc·2023-04-11·CVSS 7.8
CVE-2023-23375 [HIGH] CWE-20 Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
FAQ: I am running SQL Server on my system. What action do I need to take?
Update your rele
Microsoft
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
vendor_msrc·2023-04-11·CVSS 7.8
CVE-2023-28304 [HIGH] CWE-20 Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in which an attacker, through social engineering, convinces a victim to download and open a specially crafted file from a website which leads to a local attack on their computer.
FAQ: I am running SQL Server on my system. What action do I need to take?
Update your rele
Microsoft
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
vendor_msrc·2023-02-14·CVSS 7.8
CVE-2023-21718 [HIGH] CWE-191 Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit the vulnerability by tricking an un-authenticated user into attempting to connect to a malicious SQL server database via ODBC. This could result in the database returning malicious data that might cause arbitrary code execution on the client.
SQL Server: SQL Server
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=5521de5b-6966-4a1e-808d-93dd89c2240d
Reference: https://www.microsoft.com/download/details.aspx?familyid=ae1e0ab6-c
GHSA
GHSA-7qjv-92r9-cq7c: Microsoft SQL ODBC Driver Remote Code Execution Vulnerability
ghsa_unreviewed·2023-02-14
CVE-2023-21718 [HIGH] GHSA-7qjv-92r9-cq7c: Microsoft SQL ODBC Driver Remote Code Execution Vulnerability
Microsoft SQL ODBC Driver Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
The February 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-02-15
The February 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for February2023
Adobe Patches for February2023
Notable and Critical Microsoft Vulnerabilities Patched
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft and Adobe have released several monthly security fixes and updates for their products. Let’s take a look at the highlights of this month’s Patch Tuesday as we review and discuss the security updates.
## Microsoft Patches for February 2023
Microsoft has patched 79 vulnerabilities this month, in
Qualys
The February 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-02-15
The February 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for February2023
- Adobe Patches for February2023
- Notable and Critical Microsoft Vulnerabilities Patched
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft and Adobe have released several monthly security fixes and updates for their products. Let’s take a look at the highlights of this month’s Patch Tuesday as we review and discuss the security updates.
## Microsoft Patches for February 2023
Microsoft has patched 79 vulnerabilities t
2023-02-14
Published