Use After Free (CWE-416)
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability. This is a network-based vulnerability with low attack complexity that requires low privileges and no user interaction. It has high impacts on confidentiality, integrity, and availability.
This vulnerability allows an attacker to execute arbitrary code remotely on affected Microsoft SQL Server systems. The potential impacts include: 1. Unauthorized access to sensitive data stored in the SQL Server database. 2. Modification or deletion of critical data, potentially compromising data integrity. 3. Disruption of SQL Server services, leading to system unavailability. 4. Potential lateral movement within the network if the compromised SQL Server has connections to other systems.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released an official fix for this vulnerability as of September 10, 2024.
1. Apply the official patch released by Microsoft as soon as possible. 2. Limit network access to SQL Server instances, allowing connections only from trusted sources. 3. Implement the principle of least privilege for SQL Server accounts. 4. Regularly monitor SQL Server logs for suspicious activities. 5. Keep SQL Server and related systems up-to-date with the latest security patches. 6. Use network segmentation to isolate SQL Server instances from untrusted networks. 7. Implement strong authentication mechanisms for SQL Server access.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (380469)
A CVSS base score of 8.8 has been assigned.
Feedly found the first article mentioning CVE-2024-26186. See article
Feedly estimated the CVSS score as HIGH
NVD published the first details for CVE-2024-26186
EPSS Score was set to: 0.05% (Percentile: 20%)
Detection for the vulnerability has been added to Nessus (207067)
Detection for the vulnerability has been added to Nessus (207069)
EPSS Score was set to: 0.05% (Percentile: 17.4%)