CVE-2024-37341 is a critical Elevation of Privilege vulnerability affecting multiple versions of Microsoft SQL Server, including 2016, 2017, 2019, and 2022, as well as the 2016 Azure Connect Feature Pack. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without user interaction, allowing an unauthenticated attacker to gain full control over the affected system, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits or Metasploit modules are currently available, and it is not listed on the KEV catalog, its high FAUCET Risk Score of 83/100 and recent media coverage indicate significant concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.7000.253, < 13.0.7040.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_2016_azure_connect_feature_pack:*:*:*:*:*:*:*:* | ||
>= 13.0.6300.2, < 13.0.6441.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 14.0.1000.169, < 14.0.2060.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 14.0.3006.16, < 14.0.3475.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 15.0.2000.5, < 15.0.2120.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.