Known vulnerabilities in Microsoft Microsoft SQL Server

Vendor: Microsoft
Website: https://www.microsoft.com
Total Security Bulletins: 34

Security bulletins (34)

Secuity bulletin Severity Status Published
SB20260113135: Privilege escalation in Microsoft SQL Server Low
Patched
13.01.2026
SB2025111157: SQL injection in Microsoft SQL Server Medium
Patched
11.11.2025
SB2025090982: Multiple vulnerabilities in Microsoft SQL Server Medium
Patched
09.09.2025
SB2025081271: Multiple vulnerabilities in Microsoft SQL Server Medium
Patched
12.08.2025
SB2025070907: Multiple vulnerabilities in Microsoft SQL Server Medium
Patched
09.07.2025
SB20241112136: Remote code execution in Microsoft.SqlServer.XEvent.Configuration.dll High
Patched
12.11.2024
SB20241112114: Remote code execution in Microsoft SQL Server High
Patched
12.11.2024
SB20241112110: Multiple vulnerabilities in Microsoft SQL Server Native Client High
Patched
12.11.2024
SB20240910114: Multiple vulnerabilities in Microsoft SQL Server Native Scoring Medium
Patched
10.09.2024
SB20240910111: Multiple vulnerabilities in Microsoft SQL Server Medium
Patched
10.09.2024
SB20240709106: Heap-based buffer overflow in Microsoft OLE DB Driver for SQL Server High
Patched
09.07.2024
SB20240709103: Multiple vulnerabilities in Microsoft SQL Server Native Client OLE DB Provider High
Patched
09.07.2024
SB2024040976: Multiple vulnerabilities in Microsoft ODBC Driver for SQL Server High
Patched
09.04.2024
SB2024040964: Multiple vulnerabilities in Microsoft OLE DB Driver for SQL Server High
Patched
09.04.2024
SB2024011005: Security features bypass in Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider High
Patched
10.01.2024
SB2023101090: Denial of service in Microsoft SQL Server Low
Patched
10.10.2023
SB2023101088: Remote code execution in Microsoft SQL ODBC Driver High
Patched
10.10.2023
SB2023101083: Multiple vulnerabilities in Microsoft ODBC Driver for SQL Server High
Patched
10.10.2023
SB2023080869: Remote code execution in Microsoft OLE DB High
Patched
08.08.2023
SB2023061536: Remote code execution in Microsoft ODBC and OLE DB drivers High
Patched
15.06.2023
SB2023061535: Remote code execution in Microsoft OLE DB driver High
Patched
15.06.2023
SB2023061534: Multiple vulnerabilities in Microsoft ODBC Driver for SQL Server High
Patched
15.06.2023
SB2023041160: Remote code execution in Microsoft SQL Server High
Patched
11.04.2023
SB2023021426: Multiple vulnerabilities in Microsoft SQL Server High
Patched
14.02.2023
SB2022061453: Remote code execution in Microsoft SQL Server Medium
Patched
14.06.2022
SB2022020845: Privilege escalation in Microsoft SQL Server for Linux Containers Low
Patched
08.02.2022
SB2021011280: Privilege escalation in Microsoft SQL Server Medium
Patched
12.01.2021
SB2020021150: Remote code execution in Microsoft SQL Server Reporting Services Medium
Patched Exploited
11.02.2020
SB2019071009: Remote Code Execution in Microsoft SQL Server Medium
Patched
10.07.2019
SB2018081421: Remote buffer overflow in Microsoft SQL Server Medium
Patched
14.08.2018
SB2017080812: Information disclosure in Microsoft SQL Server Analysis Services Low
Patched
08.08.2017
SB2012081402: Remote code execution in Windows Common Controls Critical
Patched Exploited
14.08.2012
SB2012041002: Remote code execution in MSCOMCTL.OCX ActiveX control in Microsoft Office Critical
Patched Exploited
10.04.2012
SB2009101301: Multiple vulnerabilities in Microsoft Windows Critical
Patched
13.10.2009