CVE-2019-1068

HIGH(8.8)KEVWahrscheinlich ausgenutzt

Microsoft SQL Server Remote Code Execution Vulnerability

Beschreibung

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

KEV-Informationen

Hersteller
Microsoft
Produkt
SQL Server
Hinzugefügt am
26. August 2026
Fälligkeitsdatum
29. August 2026
Erforderliche Maßnahme
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
LOW
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
2.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
microsoftsql server2014
microsoftsql server 2016>= 13.0.4001.0, < 13.0.4259.0; >= 13.0.4411.0, < 13.0.4604.0; >= 13.0.5026.0, < 13.0.5101.9; >= 13.0.5149.0, < 13.0.5366.0
microsoftsql server 2017>= 14.0.1000.169, < 14.0.2027.2; >= 14.0.3006.16, < 14.0.3192.2

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Referenzen

CVSS-Score

8.8
HIGH(8.8)

EPSS-Score

EPSS-Score52.84%
EPSS-Perzentil98.9%

Daten

Veröffentlicht15. Juli 2019
Zuletzt geändert27. August 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.