Input validation error in Microsoft products - CVE-2023-36728
Published: October 10, 2023
Vulnerability identifier: #VU81827
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36728
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in Microsoft SQL Server. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Microsoft ODBC Driver for SQL Server on Linux
Microsoft ODBC Driver for SQL Server on macOS
Microsoft ODBC Driver for SQL Server on Windows
OLE DB Driver
Microsoft SQL Server
TeleControl Server Basic
Microsoft ODBC Driver for SQL Server on macOS
Microsoft ODBC Driver for SQL Server on Windows
OLE DB Driver
Microsoft SQL Server
TeleControl Server Basic
How to mitigate CVE-2023-36728
Install updates from vendor's website.
Microsoft ODBC Driver for SQL Server on Linux - addressed in versions 17.10.5.1, 18.3.2.1
Microsoft ODBC Driver for SQL Server on macOS - addressed in versions 17.10.5.1, 18.3.2.1
Microsoft ODBC Driver for SQL Server on Windows - update to 18.6.0007.0
OLE DB Driver - update to 19.3.0002.0
Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6449.1, 2014 SP3 GDR 12.0.6179.1, 2016 SP3 13.0.7029.3, 2016 SP3 GDR 13.0.6435.1, 2017 GDR 14.0.2052.1, 2017 CU31 14.0.3465.1, 2019 GDR 15.0.2104.1, 2019 CU22 15.0.4326.1, 2022 GDR 16.0.1105.1, 2022 CU8 16.0.4080.1
TeleControl Server Basic - update to 3.1.2
Microsoft ODBC Driver for SQL Server on macOS - addressed in versions 17.10.5.1, 18.3.2.1
Microsoft ODBC Driver for SQL Server on Windows - update to 18.6.0007.0
OLE DB Driver - update to 19.3.0002.0
Microsoft SQL Server - addressed in versions 2014 SP3 CU4 12.0.6449.1, 2014 SP3 GDR 12.0.6179.1, 2016 SP3 13.0.7029.3, 2016 SP3 GDR 13.0.6435.1, 2017 GDR 14.0.2052.1, 2017 CU31 14.0.3465.1, 2019 GDR 15.0.2104.1, 2019 CU22 15.0.4326.1, 2022 GDR 16.0.1105.1, 2022 CU8 16.0.4080.1
TeleControl Server Basic - update to 3.1.2