Record summary

CVE-2024-35272 has a selected CVSS score of 8.8 (high).

Description

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 9, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 13
ProductSourceVersion rangeStatus

Microsoft SQL Server 2016 Service Pack 3 (GDR)

Browse Microsoft / Microsoft SQL Server 2016 Service Pack 3 (GDR)
CVE List13.0.0 to < 13.0.6441.1affected

Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack

Browse Microsoft / Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack
CVE List13.0.0 to < 13.0.7037.1affected
CVE List14.0.0 to < 14.0.3471.2affected
CVE List15.0.0 to < 15.0.2116.2affected

Microsoft SQL Server 2019 for x64-based Systems (CU 27)

Browse Microsoft / Microsoft SQL Server 2019 for x64-based Systems (CU 27)
CVE List15.0.0 to < 15.0.4382.1affected
CVE List16.0.0 to < 16.0.1121.4affected
CVE List16.0.0 to < 16.0.4131.2affected

Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)

Browse Microsoft / Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)
CVE List15.9.0 to < 15.9.66affected

Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)

Browse Microsoft / Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)
CVE List16.11.0 to < 16.11.40affected

Microsoft Visual Studio 2022 version 17.10

Browse Microsoft / Microsoft Visual Studio 2022 version 17.10
CVE List17.10 to < 17.10.7affected

Microsoft Visual Studio 2022 version 17.11

Browse Microsoft / Microsoft Visual Studio 2022 version 17.11
CVE List17.11 to < 17.11.3affected

Microsoft Visual Studio 2022 version 17.6

Browse Microsoft / Microsoft Visual Studio 2022 version 17.6
CVE List17.6.0 to < 17.6.19affected

References

2