Input validation error in Microsoft SQL Server - CVE-2023-21704

 

Input validation error in Microsoft SQL Server - CVE-2023-21704

Published: February 14, 2023


Vulnerability identifier: #VU72180
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21704
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in Microsoft ODBC Driver for SQL Server. A remote user can pass specially crafted input to the server and execute arbitrary code on the system.


Affected software

Microsoft SQL Server
TeleControl Server Basic

How to mitigate CVE-2023-21704

Install updates from vendor's website.

Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6444.4, 2014 SP3 GDR 12.0.6174.8, 2016 SP3 13.0.7024.30, 2016 SP3 GDR 13.0.6430.49, 2017 GDR 14.0.2047.8, 2017 CU31 14.0.3460.9, 2019 GDR 15.0.2101.7, 2019 CU18 15.0.4280.7, 2022 GDR 16.0.1050.5
TeleControl Server Basic - update to 3.1.2

External References

Related Security Bulletins