CVE-2024-49002

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 15, 2024
CWE ID 122

Summary

CVE-2024-49002 is a newly disclosed vulnerability affecting SQL Server Native Client. This issue permits an unauthenticated attacker to execute arbitrary code remotely by sending specially crafted packets to the SQL Server instance. Successful exploitation could lead to significant security compromises, including data theft, unauthorized access, and system takeover. Microsoft recommends applying the available security patch or implementing workarounds to mitigate risk. Organizations using the SQL Server Native Client are urged to prioritize updating their systems to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft SQL Server

Affected Vendors

  • Microsoft