๐Ÿ” CVE Alert

CVE-2023-21705

HIGH 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Microsoft SQL Server Remote Code Execution Vulnerability

Vendor microsoft
Product microsoft sql server 2012 service pack 4 (qfe)
Ecosystems
Industries
TechnologyEnterprise
Published Feb 14, 2023
Last Updated Jan 1, 2025
Stay Ahead of the Next One

Get instant alerts for microsoft microsoft sql server 2012 service pack 4 (qfe)

Be the first to know when new high vulnerabilities affecting microsoft microsoft sql server 2012 service pack 4 (qfe) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Microsoft SQL Server 2012 Service Pack 4 (QFE)
11.0.0 < 11.0.7512.11
Microsoft / Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE)
11.0.0 < 11.0.7512.11
Microsoft / Microsoft SQL Server 2017 (GDR)
14.0.0 < 14.0.2047.8
Microsoft / Microsoft SQL Server 2014 Service Pack 3 (GDR)
12.0.0 < 12.0.6444.4
Microsoft / Microsoft SQL Server 2014 Service Pack 3 (CU 4)
12.0.0 < 12.0.6174.8
Microsoft / Microsoft SQL Server 2019 (GDR)
15.0.0 < 15.0.2101.7
Microsoft / Microsoft SQL Server 2016 Service Pack 3 (GDR)
13.0.0 < 13.0.6430.49
Microsoft / Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack
13.0.0 < 13.0.7024.30
Microsoft / Microsoft SQL Server 2017 (CU 31)
14.0.0 < 14.0.3460.9
Microsoft / Microsoft SQL Server 2022 (GDR)
16.0.0 < 16.0.1050.5
Microsoft / Microsoft SQL Server 2019 (CU 18)
15.0.0 < 15.0.4280.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21705