VDB
CVE-2023-23375
CVE-2023-23375
PUBLISHED
CVSS 7.800000190734863 HIGH
Microsoft SQL Server Remote Code Execution Vulnerability
EPSS 1.06% · 78.0th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
1.06%
78.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft SQL Server 2019 (CU 18) | 15.0.0 |
| Microsoft | Microsoft SQL Server 2019 (GDR) | 15.0.0 |
| microsoft | odbc_driver_18_for_sql_server | 18.0.0.0 |
| Microsoft | Microsoft SQL Server 2012 Service Pack 4 (QFE) | 11.0.0 |
| Microsoft | Microsoft SQL Server 2022 (GDR) | 16.0.0 |
| microsoft | ole_db_driver_19_for_sql_server | 19.0.0 |
| microsoft | ole_db | 19.1.0, 19.1.0, 18.0 |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 (CU 4) | 12.0.0 |
| Microsoft | Microsoft OLE DB Driver 19 for SQL Server | 19.0.0 |
| Microsoft | Microsoft OLE DB Driver 18 for SQL Server | 18.0.0 |
| Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | 13.0.0 |
| microsoft | sql_server | 11.0.0, 10.0.0, 14.0.0 |
| Microsoft | Microsoft SQL Server 2008 Service Pack 4 (QFE) | 10.0.0 |
| Microsoft | Microsoft SQL Server 2017 (CU 31) | 14.0.0 |
| Microsoft | Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack | 13.0.0 |
| microsoft | odbc_driver_17_for_sql_server | 17.0.0.0 |
| Microsoft | Microsoft ODBC Driver 18 for SQL Server | 18.0.0.0 |
| microsoft | odbc | 17.0, 18.0, 18.0 |
| microsoft | ole_db_driver_18_for_sql_server | 18.0.0 |
| Microsoft | Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE) | 11.0.0 |
…and 4 more
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- Microsoft SQL Server Remote Code Execution Vulnerability (circl)
- Microsoft ODBC and OLE DB Remote Code Execution Vulnerability (circl)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
- rules.yar (github-yara)
Timeline
- Apr 11, 2023 CVE Published
- Apr 12, 2023 EPSS Score
- May 20, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
- Aug 3, 2023 EPSS Score
- Oct 11, 2023 CVE Updated
- Oct 18, 2023 EPSS Score
- Nov 24, 2023 EPSS Score
- Jan 1, 2024 EPSS Score
- Feb 8, 2024 EPSS Score
- Mar 17, 2024 EPSS Score
- Apr 23, 2024 EPSS Score