← Back

CVE-2024-28929

nvd nist
Published: Apr 9, 2024Modified: Jan 14, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

Affected (15)

5 products
Sql Server 2019
Sql Server 2022
Odbc Driver For Sql Server
Visual Studio 2019
Visual Studio 2022
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
From 15.0.2000.5 to 15.0.2110.4
From 15.0.4003.23 to 15.0.4360.2
Microsoft
From 16.0.1000.6 to 16.0.1115.1
From 16.0.4003.1 to 16.0.4120.1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
From 17 to 17.10.6.1
From 18.0 to 18.3.3.1
From 17 to 17.10.6.1
From 18.0 to 18.3.3.1
From 17.0.1.1 to 17.10.6.1
From 18.0.1.1 to 18.3.3.1
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
From 16.0 to 16.11.35
Microsoft
From 17.4.0 to 17.4.18
From 17.6.0 to 17.6.14
From 17.8.0 to 17.8.9
From 17.9.0 to 17.9.6

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.