CVE-2024-37324 is a remote code execution vulnerability affecting the SQL Server Native Client OLE DB Provider across Microsoft SQL Server versions 2016, 2017, 2019, and 2022. With a CVSS score of 8.8 (HIGH), this vulnerability can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, and with no public exploit code available on platforms like Metasploit or ExploitDB, it has garnered some community discussion and media coverage, including its mention in Microsoft's July 2024 Patch Tuesday. Organizations should prioritize patching due to the high potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.0.6441.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:*:* | ||
>= 13.0.7000.253, < 13.0.7037.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:*:* | ||
< 14.0.2056.2CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:*:* | ||
>= 14.0.3456.2, < 14.0.3471.2CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:*:* | ||
< 15.0.2116.2CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.