CVE-2023-32028 is a Microsoft SQL OLE DB Remote Code Execution vulnerability affecting Microsoft SQL Server and the OLE DB Driver for SQL Server. Rated with a CVSS score of 7.8 (High), it requires local access and user interaction (e.g., clicking a malicious link) for an attacker to achieve high impact on confidentiality, integrity, and availability. Despite its severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.0.2, < 18.6.0006.0CPE matchmatch criteria | cpe:2.3:a:microsoft:ole_db_driver_for_sql_server:*:*:*:*:*:*:*:* | ||
>= 19.0.0, < 19.3.0001.0CPE matchmatch criteria | cpe:2.3:a:microsoft:ole_db_driver_for_sql_server:*:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2019:*:*:*:*:*:x64:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2022:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.