PT-2024-8604 · Microsoft · Sql Server Native Client+1

Published

2024-11-12

·

Updated

2024-11-15

·

CVE-2024-49018

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server Native Client (affected versions not specified)
Description The issue is related to errors of numerical truncation in the Native Client component of Microsoft SQL Server. It allows a remote attacker to execute arbitrary code by exploiting the vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-10173
CVE-2024-49018

Affected Products

Sql Server Native Client
Sql Server