CVE-2024-26191 is a high-severity Remote Code Execution (RCE) vulnerability affecting Microsoft SQL Server 2016, 2017, 2019, 2022, and the 2016 Azure Connect Feature Pack, specifically within the Native Scoring component. With a CVSS score of 8.8, this vulnerability allows an authenticated attacker to achieve full compromise (confidentiality, integrity, availability) with low attack complexity over the network. While not currently listed in CISA's KEV catalog, its high FAUCET Risk Score of 75/100 and notable community discussion (1 mention) and media coverage (1 article) suggest significant concern. There is currently no public exploit code available via Metasploit, Nuclei, or ExploitDB, and it is not considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.7000.253, <= 13.0.7037.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_2016_azure_connect_feature_pack:*:*:*:*:*:*:*:* | ||
>= 13.0.6300.2, < 13.0.6441.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 14.0.1000.169, < 14.0.2060.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 14.0.3006.16, < 14.0.3475.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 15.0.2000.5, < 15.0.2120.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.