CVE-2023-21568 is a Remote Code Execution vulnerability affecting Microsoft SQL Server Integration Services (VS extension) for SQL Server 2019 and 2022. This high-severity vulnerability (CVSS 7.3) requires local access, user interaction, and low privileges, allowing an attacker to achieve full compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, there is no public exploit code available, and community discussion is minimal, though it was mentioned in a BleepingComputer article regarding Microsoft's February 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019_integration_services:-:*:*:*:*:visual_studio:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2022_integration_services:-:*:*:*:*:visual_studio:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.