Input validation error in Microsoft SQL Server - CVE-2023-21528
Published: February 14, 2023
Vulnerability identifier: #VU72177
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21528
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can send specially crafted data to the SQL server and execute arbitrary code on the system.
Affected software
Microsoft SQL Server
TeleControl Server Basic
TeleControl Server Basic
How to mitigate CVE-2023-21528
Install updates from vendor's website.
Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6444.4, 2014 SP3 GDR 12.0.6174.8, 2016 SP3 13.0.7024.30, 2016 SP3 GDR 13.0.6430.49, 2017 GDR 14.0.2047.8, 2017 CU31 14.0.3460.9, 2019 GDR 15.0.2101.7, 2019 CU18 15.0.4280.7, 2022 GDR 16.0.1050.5
TeleControl Server Basic - update to 3.1.2
TeleControl Server Basic - update to 3.1.2