PT-2024-5444 · Microsoft · Sql Server Native Client Ole Db Provider+1

Published

2024-07-09

·

Updated

2024-08-20

·

CVE-2024-37323

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SQL Server Native Client OLE DB Provider (affected versions not specified)
Description The issue is related to an integer overflow in the OLE DB driver for SQL Server. Exploitation of this issue could allow a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-06093
CVE-2024-37323

Affected Products

Sql Server
Sql Server Native Client Ole Db Provider