QID 91910
Date Published: 2022-06-15
QID 91910: Microsoft SQL Server Remote Code Execution (RCE) Vulnerability for June 2022
Microsoft SQL Server Remote Code Execution Vulnerability.
Affected Software:
SQL Server 2019 RTM GDR
SQL Server 2019 RTM CU16
SQL Server 2017 RTM GDR
SQL Server 2017 RTM CU29
SQL Server 2016 Service Pack 2 (GDR)
SQL Server 2016 Service Pack 2 CU17
SQL Server 2016 Service Pack 3
SQL Server 2016 Service Pack 3 Azure Connectivity Pack
SQL Server 2014 Service Pack 3 (GDR)
SQL Server 2014 Service Pack 3 CU4
QID Detection Logic (Authenticated):
Detection looks for Microsoft SQL Server instances and checks sqlservr.exe file version
An authenticated attacker could exploit the vulnerability by executing a specially crafted query using $ partition against a table with a Column Store index.
Solution
Customers are advised to refer to CVE-2022-29143 for more details pertaining to this vulnerability.
Vendor References
- CVE-2022-29143 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29143
CVEs related to QID 91910
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Microsoft SQL Server |
|