Out-of-bounds Read (CWE-125)
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability. This is an out-of-bounds read vulnerability affecting various versions of Microsoft SQL Server and related products. The vulnerability has a CVSS v3.1 base score of 4.3, indicating a relatively low severity. It requires network access and low privileges to exploit, with no user interaction needed.
If exploited, this vulnerability could lead to unauthorized disclosure of information. The impact is limited to confidentiality, with a low impact rating. There is no impact on system integrity or availability. An attacker with network access and low privileges could potentially read data outside of intended boundaries, which could expose sensitive information stored in the SQL Server.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patches are available. Microsoft has released updates to address this vulnerability. The following versions should be updated: - SQL Server 2016 Azure Connect Feature Pack: Update to version later than 13.0.7037.1 - SQL Server 2022: Update to version 16.0.4140.3 or later - SQL Server 2017: Update to version 14.0.3475.1 or later - SQL Server 2019: Update to version 15.0.4390.2 or later - SQL Server 2016: Update to a version later than 13.0.6441.1
1. Apply the latest security updates provided by Microsoft for the affected SQL Server versions. 2. Ensure that SQL Server instances are not directly exposed to untrusted networks. 3. Implement the principle of least privilege for SQL Server access. 4. Monitor SQL Server logs for any suspicious activities or unauthorized access attempts. 5. Keep all SQL Server components and related software up to date with the latest security patches.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C
Detection for the vulnerability has been added to Qualys (380469)
A CVSS base score of 7.1 has been assigned.
Feedly found the first article mentioning CVE-2024-37342. See article
Feedly estimated the CVSS score as HIGH
NVD published the first details for CVE-2024-37342
Feedly estimated the CVSS score as MEDIUM
EPSS Score was set to: 0.05% (Percentile: 18.8%)
Detection for the vulnerability has been added to Nessus (207067)
Detection for the vulnerability has been added to Nessus (207069)