CVE-2024-28943 is a remote code execution vulnerability in the Microsoft ODBC Driver for SQL Server, affecting versions of SQL Server 2019 and 2022. This vulnerability has a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, its high EPSS and FAUCET risk scores, along with community discussion and media coverage, suggest significant attention. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not yet actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0.1.1, < 17.10.6.1CPE matchmatch criteria | cpe:2.3:a:microsoft:odbc_driver_for_sql_server:*:*:*:*:*:linux:*:* | ||
>= 17.0.1.1, < 17.10.6.1CPE matchmatch criteria | cpe:2.3:a:microsoft:odbc_driver_for_sql_server:*:*:*:*:*:macos:*:* | ||
>= 17.0.1.1, < 17.10.6.1CPE matchmatch criteria | cpe:2.3:a:microsoft:odbc_driver_for_sql_server:*:*:*:*:*:windows:*:* | ||
>= 18.0.1.1, < 18.3.3.1CPE matchmatch criteria | cpe:2.3:a:microsoft:odbc_driver_for_sql_server:*:*:*:*:*:linux:*:* | ||
>= 18.0.1.1, < 18.3.3.1CPE matchmatch criteria | cpe:2.3:a:microsoft:odbc_driver_for_sql_server:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.