Input validation error in Microsoft SQL Server - CVE-2023-21713

 

Input validation error in Microsoft SQL Server - CVE-2023-21713

Published: February 14, 2023


Vulnerability identifier: #VU72176
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21713
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote user can send specially crafted data to the SQL server and execute arbitrary code on the system.


Affected software

Microsoft SQL Server
TeleControl Server Basic

How to mitigate CVE-2023-21713

Install updates from vendor's website.

Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6444.4, 2014 SP3 GDR 12.0.6174.8, 2016 SP3 13.0.7024.30, 2016 SP3 GDR 13.0.6430.49, 2017 GDR 14.0.2047.8, 2017 CU31 14.0.3460.9, 2019 GDR 15.0.2101.7, 2019 CU18 15.0.4280.7, 2022 GDR 16.0.1050.5
TeleControl Server Basic - update to 3.1.2

External References

Related Security Bulletins