cbcvebase.
CVE-2024-37323
published 2024-07-09

CVE-2024-37323: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Affected

21 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sql_server_2016_service_pack_3>= 13.0.0 < 13.0.6441.113.0.6441.1
microsoftmicrosoft_sql_server_2016_service_pack_3_azure_connect_feature_pack>= 13.0.0 < 13.0.7037.113.0.7037.1
microsoftmicrosoft_sql_server_2017>= 14.0.0 < 14.0.2056.214.0.2056.2
microsoftmicrosoft_sql_server_2017>= 14.0.0 < 14.0.3471.214.0.3471.2
microsoftmicrosoft_sql_server_2019>= 15.0.0 < 15.0.2116.215.0.2116.2
microsoftmicrosoft_sql_server_2019_for_x64-based_systems>= 15.0.0 < 15.0.4382.115.0.4382.1
microsoftmicrosoft_sql_server_2022>= 16.0.0 < 16.0.1121.416.0.1121.4
microsoftmicrosoft_sql_server_2022_for>= 16.0.0 < 16.0.4131.216.0.4131.2
microsoftsql_server_2016< 13.0.6441.113.0.6441.1
microsoftsql_server_2016>= 13.0.7000.253 < 13.0.7037.113.0.7037.1
microsoftsql_server_2017< 14.0.2056.214.0.2056.2
microsoftsql_server_2017>= 14.0.3456.2 < 14.0.3471.214.0.3471.2
microsoftsql_server_2019< 15.0.2116.215.0.2116.2
microsoftsql_server_2019>= 15.0.4375.4 < 15.0.4382.115.0.4382.1
microsoftsql_server_2022< 16.0.1121.416.0.1121.4
microsoftsql_server_2022>= 16.0.4125.3 < 16.0.4131.216.0.4131.2
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3_azure_connect_fea
msrcmicrosoft_sql_server_2017_for_x64-based_systems
msrcmicrosoft_sql_server_2019_for_x64-based_systems
msrcmicrosoft_sql_server_2022_for_x64-based_systems