Lucene search

K
cvelistMicrosoftCVELIST:CVE-2023-21568
HistoryFeb 14, 2023 - 7:32 p.m.

CVE-2023-21568 Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability

2023-02-1419:32:51
CWE-502
microsoft
www.cve.org
5
cve-2023-21568
microsoft sql server
integration service
remote code execution
vulnerability

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

48.6%

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "SQL Server Integration Services for Visual Studio 2019",
    "cpes": [
      "cpe:2.3:a:microsoft:sql_server:2019:integration_services:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "16.0.0",
        "lessThan": "16.0.5035.3",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "SQL Server Integration Services for Visual Studio 2022",
    "cpes": [
      "cpe:2.3:a:microsoft:sql_server:2022:integration_services:*:*:*:*:*:*"
    ],
    "platforms": [
      "Unknown"
    ],
    "versions": [
      {
        "version": "16.0.0",
        "lessThan": "16.0.5035.3",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

48.6%