QID 92029

Date Published: 2023-06-29

QID 92029: Microsoft SQL Server Multiple Vulnerabilities

Microsoft SQL Server prone to Remote Code Execution Vulnerability. Affected Software:
SQL Server 2022 CU3
SQL Server 2019 CU20
QID Detection Logic (Authenticated):
Detection looks for Microsoft SQL Server instances and checks sqlservr.exe file version

Successful exploitation could lead to remote code execution

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to KB5024276 KB5024396 for more details pertaining to this vulnerability.

    CVEs related to QID 92029

    Software Advisories
    Advisory ID Software Component Link
    KB5024276 URL Logo support.microsoft.com/help/5024276
    KB5024396 URL Logo support.microsoft.com/help/5024396