PT-2024-5371 · Microsoft · Sql Server Native Client Ole Db Provider+1
Yuki Chen
·
Published
2024-07-09
·
Updated
2024-08-20
·
CVE-2024-37336
CVSS v2.0
10
High
| AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SQL Server Native Client OLE DB Provider (affected versions not specified)
Description
The issue is related to an integer overflow in the SQL Server Native Client OLE DB Provider. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sql Server
Sql Server Native Client Ole Db Provider