8.8

CVE-2024-28939

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ole Db Driver For Sql Server Version >= 18.0.2 < 18.7.0002.0
Microsoft ≫ Ole Db Driver For Sql Server Version >= 19.0.0 < 19.3.0003.0
Microsoft ≫ Sql Server 2019 HwPlatform x64 Version >= 15.0.2000.5 < 15.0.2110.4
Microsoft ≫ Sql Server 2019 HwPlatform x64 Version >= 15.0.4003.23 < 15.0.4360.2
Microsoft ≫ Sql Server 2022 HwPlatform x64 Version >= 16.0.1000.6 < 16.0.1115.1
Microsoft ≫ Sql Server 2022 HwPlatform x64 Version >= 16.0.4003.1 < 16.0.4120.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.27% 0.808
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-209 Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-28939
Vendor Advisory