PT-2024-5371 · Microsoft · Sql Server Native Client Ole Db Provider+1

Yuki Chen

·

Published

2024-07-09

·

Updated

2024-08-20

·

CVE-2024-37336

CVSS v2.0

10

High

AV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SQL Server Native Client OLE DB Provider (affected versions not specified)
Description The issue is related to an integer overflow in the SQL Server Native Client OLE DB Provider. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-06004
CVE-2024-37336

Affected Products

Sql Server
Sql Server Native Client Ole Db Provider