CVE-2019-1068 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

EPSS 41.57% · 97.4th percentile

Risk Scores

CVSS v3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
41.57%
97.4th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)unspecified
MicrosoftMicrosoft SQL Server2014 Service Pack 2 for 32-bit Systems (CU), 2014 Service Pack 2 for x64-based Systems (CU), 2016 for x64-based Systems Service Pack 1 (CU)
microsoftsql_server2014, 2017, 2016
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)unspecified
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)unspecified
MicrosoftMicrosoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)unspecified
MicrosoftMicrosoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)unspecified
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)unspecified
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)unspecified
MicrosoftMicrosoft SQL Server 2017 for x64-based Systems (GDR)unspecified
MicrosoftMicrosoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)unspecified

Timeline

References

Open in Interactive Console →