IT

Tracker / CVE-2024-37336

CVE-2024-37336

High 8.8

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Affected products and versions

microsoft sql_server_2016 · … → 13.0.6441.1
microsoft sql_server_2016 · 13.0.7000.253 → 13.0.7037.1
microsoft sql_server_2017 · … → 14.0.2056.2
microsoft sql_server_2017 · 14.0.3456.2 → 14.0.3471.2
microsoft sql_server_2019 · … → 15.0.2116.2
microsoft sql_server_2019 · 15.0.4375.4 → 15.0.4382.1
microsoft sql_server_2022 · … → 16.0.1121.4
microsoft sql_server_2022 · 16.0.4125.3 → 16.0.4131.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References