8.8
CVE-2024-30006
- EPSS 1.72%
- Veröffentlicht 14.05.2024 17:16:35
- Zuletzt bearbeitet 16.01.2025 19:11:30
- Erkennungen
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1507 HwPlatform x64 Version < 10.0.10240.20651
Microsoft ≫ Windows 10 1507 HwPlatform x86 Version < 10.0.10240.20651
Microsoft ≫ Windows 10 1607 HwPlatform x64 Version < 10.0.14393.6981
Microsoft ≫ Windows 10 1607 HwPlatform x86 Version < 10.0.14393.6981
Microsoft ≫ Windows 10 1809 Version < 10.0.17763.5820
Microsoft ≫ Windows 10 21h2 Version < 10.0.19044.4412
Microsoft ≫ Windows 10 22h2 Version < 10.0.19045.4412
Microsoft ≫ Windows 11 21h2 Version < 10.0.22000.2960
Microsoft ≫ Windows 11 22h2 Version < 10.0.22621.3593
Microsoft ≫ Windows 11 23h2 Version < 10.0.22631.3593
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.6981
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.5820
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.2461
Microsoft ≫ Windows Server 2022 23h2 Version < 10.0.25398.887
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.72% | 0.744 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30006