QID 92001
QID 92001: Microsoft SQL Server Remote Code Execution (RCE) Vulnerability for April 2023
Microsoft SQL Server prone to Remote Code Execution Vulnerability.
Affected Software:
SQL Server 2022 RTM (GDR)
SQL Server 2019 RTM (GDR,CU18)
SQL Server 2017 RTM (GDR,CU31)
SQL Server 2016 Service Pack 3(GDR)
SQL Server 2014 Service Pack 3 (GDR, CU4)
SQL Server 2012 SP4 (GDR)
SQL Server SQL2008R2 SP3 (GDR)
SQL Server 2008 SP4 (GDR)
QID Detection Logic (Authenticated):
Detection looks for Microsoft SQL Server instances and checks sqlservr.exe file version
Successful exploitation could lead to remote code execution
Solution
Vendor References
- CVE-2023-23384 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23384
CVEs related to QID 92001
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5020863 |
|
||
| KB5021037 |
|
||
| KB5021045 |
|
||
| KB5021112 |
|
||
| KB5021122 |
|
||
| KB5021123 |
|
||
| KB5021124 |
|
||
| KB5021125 |
|
||
| KB5021126 |
|
||
| KB5021127 |
|
||
| KB5021128 |
|
||
| KB5021129 |
|