Lucene search

K
cveMicrosoftCVE-2023-38169
HistoryAug 08, 2023 - 6:15 p.m.

CVE-2023-38169

2023-08-0818:15:22
CWE-416
microsoft
web.nvd.nist.gov
587
cve-2023-38169
microsoft
sql
ole db
remote code execution
vulnerability
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.019

Percentile

88.9%

Microsoft SQL OLE DB Remote Code Execution Vulnerability

Affected configurations

Nvd
Vulners
Node
microsoftodbc_driver_for_sql_serverMatch17.0.1.1linux
OR
microsoftodbc_driver_for_sql_serverMatch17.0.1.1macos
OR
microsoftodbc_driver_for_sql_serverMatch17.0.1.1windows
OR
microsoftodbc_driver_for_sql_serverMatch17.10.3.1linux
OR
microsoftodbc_driver_for_sql_serverMatch17.10.3.1macos
OR
microsoftodbc_driver_for_sql_serverMatch17.10.3.1windows
OR
microsoftodbc_driver_for_sql_serverMatch17.10.4.1linux
OR
microsoftodbc_driver_for_sql_serverMatch17.10.4.1macos
OR
microsoftodbc_driver_for_sql_serverMatch18.0.1.1linux
OR
microsoftodbc_driver_for_sql_serverMatch18.0.1.1macos
OR
microsoftodbc_driver_for_sql_serverMatch18.0.1.1windows
OR
microsoftodbc_driver_for_sql_serverMatch18.1.2.1linux
OR
microsoftodbc_driver_for_sql_serverMatch18.1.2.1macos
OR
microsoftodbc_driver_for_sql_serverMatch18.1.2.1windows
OR
microsoftodbc_driver_for_sql_serverMatch18.2.1.1linux
OR
microsoftodbc_driver_for_sql_serverMatch18.2.1.1macos
OR
microsoftodbc_driver_for_sql_serverMatch18.2.1.1windows
OR
microsoftole_db_driver_for_sql_serverMatch18.0.2
OR
microsoftole_db_driver_for_sql_serverMatch18.1.0
OR
microsoftole_db_driver_for_sql_serverMatch18.2.1
OR
microsoftole_db_driver_for_sql_serverMatch18.2.2
OR
microsoftole_db_driver_for_sql_serverMatch18.2.3
OR
microsoftole_db_driver_for_sql_serverMatch18.3.0
OR
microsoftole_db_driver_for_sql_serverMatch18.4.0
OR
microsoftole_db_driver_for_sql_serverMatch18.5.0
OR
microsoftole_db_driver_for_sql_serverMatch18.6.0
OR
microsoftole_db_driver_for_sql_serverMatch19.0.0
OR
microsoftole_db_driver_for_sql_serverMatch19.1.0
OR
microsoftole_db_driver_for_sql_serverMatch19.2.0
OR
microsoftole_db_driver_for_sql_serverMatch19.3.0
OR
microsoftsql_serverMatch2019x64
OR
microsoftsql_serverMatch2022x64
VendorProductVersionCPE
microsoftodbc_driver_for_sql_server17.0.1.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.0.1.1:*:*:*:*:linux:*:*
microsoftodbc_driver_for_sql_server17.0.1.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.0.1.1:*:*:*:*:macos:*:*
microsoftodbc_driver_for_sql_server17.0.1.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.0.1.1:*:*:*:*:windows:*:*
microsoftodbc_driver_for_sql_server17.10.3.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.10.3.1:*:*:*:*:linux:*:*
microsoftodbc_driver_for_sql_server17.10.3.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.10.3.1:*:*:*:*:macos:*:*
microsoftodbc_driver_for_sql_server17.10.3.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.10.3.1:*:*:*:*:windows:*:*
microsoftodbc_driver_for_sql_server17.10.4.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.10.4.1:*:*:*:*:linux:*:*
microsoftodbc_driver_for_sql_server17.10.4.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:17.10.4.1:*:*:*:*:macos:*:*
microsoftodbc_driver_for_sql_server18.0.1.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:18.0.1.1:*:*:*:*:linux:*:*
microsoftodbc_driver_for_sql_server18.0.1.1cpe:2.3:a:microsoft:odbc_driver_for_sql_server:18.0.1.1:*:*:*:*:macos:*:*
Rows per page:
1-10 of 321

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "Microsoft OLE DB Driver 19 for SQL Server",
    "cpes": [
      "cpe:2.3:a:microsoft:ole_db_driver_19_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "19.0.0",
        "lessThan": "19.3.0001.0",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft OLE DB Driver 18 for SQL Server",
    "cpes": [
      "cpe:2.3:a:microsoft:ole_db_driver_18_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "18.0.0",
        "lessThan": "18.6.0006.0",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft ODBC Driver 18 for SQL Server on Linux",
    "cpes": [
      "cpe:2.3:a:microsoft:odbc_driver_18_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "18.0.0.0",
        "lessThan": "18.2.1.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft ODBC Driver 17 for SQL Server on MacOS",
    "cpes": [
      "cpe:2.3:a:microsoft:odbc_driver_17_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "17.0.0.0",
        "lessThan": "17.10.4.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft SQL Server 2022 (CU 5)",
    "cpes": [
      "cpe:2.3:a:microsoft:sql_server:2022:*:*:*:*:*:x64:*"
    ],
    "platforms": [
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "15.0.0",
        "lessThan": "16.0.4053.3",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft ODBC Driver 17 for SQL Server on Linux",
    "cpes": [
      "cpe:2.3:a:microsoft:odbc_driver_17_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "17.0.0.0",
        "lessThan": "17.10.4.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft ODBC Driver 18 for SQL Server on MacOS",
    "cpes": [
      "cpe:2.3:a:microsoft:odbc_driver_18_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "18.0.0.0",
        "lessThan": "18.2.1.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft SQL Server 2019 (CU 21)",
    "cpes": [
      "cpe:2.3:a:microsoft:sql_server:2019:*:*:*:*:*:x64:*"
    ],
    "platforms": [
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "15.0.0",
        "lessThan": "15.0.4316.3",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft ODBC Driver 17 for SQL Server on Windows",
    "cpes": [
      "cpe:2.3:a:microsoft:odbc_driver_17_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "17.0.0.0",
        "lessThan": "17.10.4.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft ODBC Driver 18 for SQL Server on Windows",
    "cpes": [
      "cpe:2.3:a:microsoft:odbc_driver_18_for_sql_server:-:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "18.0.0.0",
        "lessThan": "18.2.2.1",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.019

Percentile

88.9%