CVE-2019-1068
HIGH(8.8)KEVWahrscheinlich ausgenutzt
Microsoft SQL Server Remote Code Execution Vulnerability
Beschreibung
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| microsoft | sql server | 2014 |
| microsoft | sql server 2016 | >= 13.0.4001.0, < 13.0.4259.0; >= 13.0.4411.0, < 13.0.4604.0; >= 13.0.5026.0, < 13.0.5101.9; >= 13.0.5149.0, < 13.0.5366.0 |
| microsoft | sql server 2017 | >= 14.0.1000.169, < 14.0.2027.2; >= 14.0.3006.16, < 14.0.3192.2 |
Mehrere CVSS-Bewertungen
Quelle: [email protected](Primary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Referenzen
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1068(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.