CVE-2024-43519

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 17, 2024
CWE ID 197

Summary

CVE-2024-43519 is a newly disclosed vulnerability affecting the Microsoft Windows Defender Application Control (WDAC) OLE DB provider for SQL Server. This issue allows an attacker to execute arbitrary code remotely, potentially leading to a serious compromise of affected systems. The vulnerability is believed to arise from insufficient input validation in the way the provider handles specially crafted OLE DB queries. Microsoft has released a security advisory and patch to address this issue, and it is strongly recommended that users install the update as soon as possible to mitigate the risk. Failure to do so may expose systems to remote code execution attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share