Input validation error in Microsoft SQL Server - CVE-2023-21568

 

Input validation error in Microsoft SQL Server - CVE-2023-21568

Published: February 14, 2023


Vulnerability identifier: #VU72179
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21568
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the Microsoft SQL Server Integration Service (VS extension). A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the server.


Affected software

Microsoft SQL Server
TeleControl Server Basic

How to mitigate CVE-2023-21568

Install updates from vendor's website.

Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6444.4, 2014 SP3 GDR 12.0.6174.8, 2016 SP3 13.0.7024.30, 2016 SP3 GDR 13.0.6430.49, 2017 GDR 14.0.2047.8, 2017 CU31 14.0.3460.9, 2019 GDR 15.0.2101.7, 2019 CU18 15.0.4280.7, 2022 GDR 16.0.1050.5
TeleControl Server Basic - update to 3.1.2

External References

Related Security Bulletins