Input validation error in Microsoft SQL Server - CVE-2023-21568
Published: February 14, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the Microsoft SQL Server Integration Service (VS extension). A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the server.
Affected software
TeleControl Server Basic
How to mitigate CVE-2023-21568
TeleControl Server Basic - update to 3.1.2