CVE-2024-49014

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 15, 2024
CWE ID 415

Summary

CVE-2024-49014 is a newly disclosed vulnerability affecting SQL Server Native Client. The issue grants an attacker the ability to execute arbitrary code remotely by exploiting a vulnerability in the component's handling of unsecured connections. Successful exploitation could lead to significant data loss, unauthorized access, or system compromise. It is strongly advised that affected organizations apply the forthcoming patch or update their configurations to mitigate this risk. SQL Server Native Client users are urged to stay vigilant and ensure their systems are secure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft SQL Server

Affected Vendors

  • Microsoft