Heap-based Buffer Overflow (CWE-122)
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability. This is a network-based vulnerability with low attack complexity and requires low privileges to exploit. It does not require user interaction and can lead to high impacts on confidentiality, integrity, and availability.
This vulnerability allows attackers to execute arbitrary code remotely on affected SQL Server instances. Successful exploitation could result in unauthorized access to sensitive data, modification of database contents, and potential disruption of database services. The high impact on confidentiality, integrity, and availability suggests that attackers could potentially gain full control over the affected SQL Server, compromising all aspects of data security and system functionality.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released an official fix for this vulnerability as of September 10, 2024.
1. Apply the official patch released by Microsoft as soon as possible. 2. Limit network access to SQL Server instances, allowing connections only from trusted sources. 3. Implement the principle of least privilege for SQL Server user accounts. 4. Monitor SQL Server logs for any suspicious activities. 5. Keep SQL Server and related components up to date with the latest security patches. 6. Use firewalls and network segmentation to isolate SQL Server instances from untrusted networks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (380469)
A CVSS base score of 8.8 has been assigned.
Feedly found the first article mentioning CVE-2024-37335. See article
Feedly estimated the CVSS score as HIGH
NVD published the first details for CVE-2024-37335
EPSS Score was set to: 0.05% (Percentile: 20%)
Detection for the vulnerability has been added to Nessus (207067)
Detection for the vulnerability has been added to Nessus (207069)
EPSS Score was set to: 0.05% (Percentile: 17.5%)