cbcvebase.
CVE-2024-49018
published 2024-11-12

CVE-2024-49018: SQL Server Native Client Remote Code Execution Vulnerability

PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.52%
71.7th percentile
SQL Server Native Client Remote Code Execution Vulnerability

Affected

16 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sql_server_2016_service_pack_3>= 13.0.0 < 13.0.6455.213.0.6455.2
microsoftmicrosoft_sql_server_2016_service_pack_3_azure_connect_feature_pack>= 13.0.0 < 13.0.7050.213.0.7050.2
microsoftmicrosoft_sql_server_2017>= 14.0.0 < 14.0.2070.114.0.2070.1
microsoftmicrosoft_sql_server_2017>= 14.0.0 < 14.0.3485.114.0.3485.1
microsoftmicrosoft_sql_server_2019>= 15.0.0 < 15.0.2130.315.0.2130.3
microsoftmicrosoft_sql_server_2019>= 15.0.0 < 15.0.4410.115.0.4410.1
microsoftsql_server_2016>= 13.0.6300.2 < 13.0.6455.213.0.6455.2
microsoftsql_server_2016>= 13.0.7000.253 < 13.0.7050.213.0.7050.2
microsoftsql_server_2017>= 14.0.1000.169 < 14.0.2070.114.0.2070.1
microsoftsql_server_2017>= 14.0.3006.16 < 14.0.3485.114.0.3485.1
microsoftsql_server_2019>= 15.0.2000.5 < 15.0.2130.315.0.2130.3
microsoftsql_server_2019>= 15.0.4003.23 < 15.0.4410.115.0.4410.1
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3
msrcmicrosoft_sql_server_2016_for_x64-based_systems_service_pack_3_azure_connect_fea
msrcmicrosoft_sql_server_2017_for_x64-based_systems
msrcmicrosoft_sql_server_2019_for_x64-based_systems

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to connect to a malicious SQL server database via a connection driver (OLE DB / OLEDB); monitor for unexpected outbound SQL Server connections initiated by client applications to untrusted hosts.
  • The attack is client-side RCE triggered by malicious server responses; focus detection on SQL Server Native Client library (sqlncli) loading and abnormal child process spawning from applications making OLE DB connections.
  • ·Exploit status is confirmed as not publicly disclosed and not exploited in the wild at time of advisory publication; exploitation is rated 'Less Likely' for the latest software release.
  • ·Customer action (patching) is explicitly required; multiple SQL Server builds are affected, each with a distinct patch package referenced via separate KB articles and download family IDs.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.