Numeric Truncation Error (CWE-197)
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability. This vulnerability affects multiple versions of Microsoft SQL Server, including SQL Server 2016, 2017, 2019, and 2022, as well as SQL 2016 Azure Connect Feature Pack. The vulnerability is related to a numeric truncation error, which could potentially lead to information disclosure.
This vulnerability allows a remote attacker with low privileges to potentially access sensitive information. The attack vector is network-based and does not require user interaction. While the confidentiality impact is low, it could still expose some sensitive data. There is no impact on system integrity or availability.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Microsoft has released updates to address this vulnerability. The patch was initially added on September 10, 2024, and updated information was provided on September 23, 2024.
To mitigate this vulnerability, it is recommended to apply the latest security updates provided by Microsoft for the affected SQL Server versions. Specifically: 1. For SQL Server 2017, update to version 14.0.3475.1 or later. 2. For SQL Server 2022, update to version 16.0.4140.3 or later. 3. For SQL Server 2016, update to version 13.0.6441.1 or later. 4. For SQL Server 2019, update to version 15.0.4390.2 or later. 5. For SQL 2016 Azure Connect Feature Pack, update to a version later than 13.0.7037.1. Additionally, implement network segmentation and access controls to limit exposure of SQL Server instances to untrusted networks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (380469)
A CVSS base score of 7.1 has been assigned.
Feedly found the first article mentioning CVE-2024-37337. See article
Feedly estimated the CVSS score as HIGH
NVD published the first details for CVE-2024-37337
Feedly estimated the CVSS score as MEDIUM
EPSS Score was set to: 0.05% (Percentile: 18.8%)
Detection for the vulnerability has been added to Nessus (207067)
Detection for the vulnerability has been added to Nessus (207069)