Microsoft Sql Server 2017
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Sql Server 2017.
By the Year
In 2026 there have been 2 vulnerabilities in Microsoft Sql Server 2017 with an average score of 8.8 out of ten. Last year, in 2025 Sql Server 2017 had 8 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Sql Server 2017 in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.45.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 8.80 |
| 2025 | 8 | 8.35 |
| 2024 | 81 | 8.65 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 1 | 0.00 |
It may take a day or so for new Sql Server 2017 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Sql Server 2017 Security Vulnerabilities
Mar 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-26115
8.8 - High
- March 10, 2026
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper Validation of Specified Type of Input
Mar 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-21262
8.8 - High
- March 10, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Authorization
Nov 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-59499
8.8 - High
- November 11, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Sep 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-55227
8.8 - High
- September 09, 2025
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Command Injection
Sep 2025: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2025-47997
6.5 - Medium
- September 09, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
Race Condition
Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49759
8.8 - High
- August 12, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-53727
8.8 - High
- August 12, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49758
8.8 - High
- August 12, 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper Privilege Management
Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-24999
8.8 - High
- August 12, 2025
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Authorization
Jul 2025: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2025-49719
7.5 - High
- July 08, 2025
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
Improper Input Validation
SQL Server Native Client RCE via Remote Execution
CVE-2024-49003
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Dangling pointer
RCE in Microsoft SQL Server Native Client
CVE-2024-49016
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Dangling pointer
MS SQLServer Native Client RCE via Remote Code Exec
CVE-2024-49004
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability CVE-2024-49005
CVE-2024-49005
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Remote Code Execution Vulnerability
CVE-2024-49006
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability
CVE-2024-49007
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE (CVE-2024-49009)
CVE-2024-49009
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
CVE-2024-49010: MS SQL Server Native Client RCE Vulnerability
CVE-2024-49010
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability
CVE-2024-49011
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability (CVE-2024-49012)
CVE-2024-49012
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE via Native Client Driver
CVE-2024-49013
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability in 2024
CVE-2024-49014
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Microsoft SQL Server Native Client RCE Vulnerability
CVE-2024-49015
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49008
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client Remote RCE Vulnerability
CVE-2024-49002
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft SQL Server Native Client RCE Remote Code Exec
CVE-2024-49001
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE via Remote Code Execution
CVE-2024-49000
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
MS SQL Server Native Client RCE via Remote Exploit
CVE-2024-48999
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft SQL Server Native Client RCE via Remote Exec
CVE-2024-48998
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client Remote RCE Vulnerability
CVE-2024-48997
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
SQL Server Native Client RCE via Remote Vulnerability
CVE-2024-48996
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability (Remote Code Exec)
CVE-2024-48995
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability (CVE-2024-48994)
CVE-2024-48994
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft SQL Server Native Client RCE (CVE-2024-38255)
CVE-2024-38255
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Remote Code Execution in Microsoft SQL Server Native Client
CVE-2024-48993
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
SQL Server Native Client RCE Vulnerability in Microsoft's Database Client
CVE-2024-43462
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Remote Code Execution in Microsoft SQL Server Native Client
CVE-2024-43459
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Dangling pointer
SQL Server Native Client: Remote Code Execution Vulnerability
CVE-2024-49018
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Numeric Truncation Error
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2024-49021
7.8 - High
- November 12, 2024
Microsoft SQL Server Remote Code Execution Vulnerability
Dangling pointer
Microsoft SQL Server XEvent Configuration Remote Code Execution Vulnerability
CVE-2024-49043
7.8 - High
- November 12, 2024
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
Untrusted Path
SQL Server Native Client: Remote Code Execution Vulnerability
CVE-2024-49017
8.8 - High
- November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft SQL Server Elevation of Privilege Vulnerability CVE-2024-37341
CVE-2024-37341
9.8 - Critical
- September 10, 2024
Microsoft SQL Server Elevation of Privilege Vulnerability
Authorization
Microsoft SQL Server EoP Vulnerability
CVE-2024-37965
8.8 - High
- September 10, 2024
Microsoft SQL Server Elevation of Privilege Vulnerability
Improper Input Validation
MS SQL Server Info Disclosure via CVE-2024-43474
CVE-2024-43474
7.5 - High
- September 10, 2024
Microsoft SQL Server Information Disclosure Vulnerability
Improper Null Termination
Microsoft SQL Server EOP Vulnerability CVE-2024-37980
CVE-2024-37980
9.8 - Critical
- September 10, 2024
Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Info Disclosure via Native Scoring Function
CVE-2024-37966
7.1 - High
- September 10, 2024
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Out-of-bounds Read
SQL Server Native Scoring Info Disclosure Vulnerability
CVE-2024-37342
4.3 - Medium
- September 10, 2024
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Out-of-bounds Read
Remote Code Execution in Microsoft SQL Server Native Scoring
CVE-2024-37340
8.8 - High
- September 10, 2024
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Untrusted Pointer Dereference
Microsoft SQL Server RCE via Native Scoring
CVE-2024-37339
8.8 - High
- September 10, 2024
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Microsoft SQL Server RCE via Native Scoring
CVE-2024-37338
8.8 - High
- September 10, 2024
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
Out-of-bounds Read
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2017 or by Microsoft? Click the Watch button to subscribe.