QID 92009
Date Published: 2023-07-10
QID 92009: Microsoft SQL ODBC and OLE DB Driver Remote Code Execution (RCE) Vulnerability for April 2023
OLE DB and ODBC are APIs for Microsoft SQL server that provide access to a range of data sources
Affected Software:
Microsoft ODBC Driver 18 for SQL Server before 18.2.1.1
Microsoft OLE DB Driver 19 for SQL Server before 19.3.0
Microsoft ODBC Driver 17 for SQL Server before 17.10.3.1
Microsoft OLE DB Driver 18 for SQL Server before 18.6.5
QID Detection Logic (Authenticated):
Detection looks for vulnerable driver file version
Successful exploitation could lead to remote code execution
Solution
Customers are advised to refer to
CVE-2023-28304
CVE-2023-23375
Vendor References
- CVE-2023-23375 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23375 - CVE-2023-28304 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28304
CVEs related to QID 92009
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-23375 |
|
||
| CVE-2023-28304 |
|