CVE-2024-29047
vulnerability analysis and mitigation

Overview

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability (CVE-2024-29047) is a security flaw that affects Microsoft SQL Server systems. The vulnerability was discovered and disclosed on April 9, 2024, impacting Microsoft OLE DB Driver versions 18 and 19 for SQL Server (Microsoft Update).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerability is classified as a heap-based buffer overflow (CWE-122) (NVD).

Impact

The vulnerability could allow remote code execution when a client connects to a malicious server that sends malicious data, potentially compromising the client system (Tech Community).

Exploitability

The vulnerability requires user interaction and involves connecting to a malicious server that sends malicious data to compromise a client (Tech Community).

Mitigation and workarounds

Microsoft has released security updates to address this vulnerability. The fixes are available through Windows Update, standalone download packages, and are included in SQL Server 2019 and SQL Server 2022 updates released on April 9, 2024. For OLE DB Driver 18, update to version 18.7.2, and for OLE DB Driver 19, update to version 19.3.3 (Microsoft Update).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management