#VU72179 Input validation error in Microsoft SQL Server - CVE-2023-21568
Published: February 14, 2023
Microsoft SQL Server
Microsoft
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the Microsoft SQL Server Integration Service (VS extension). A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the server.