RCE in Microsoft SQL Server Native Client
CVE-2024-49016 Published on November 12, 2024
SQL Server Native Client Remote Code Execution Vulnerability
SQL Server Native Client Remote Code Execution Vulnerability
Weakness Type
What is a Dangling pointer Vulnerability?
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
CVE-2024-49016 has been classified to as a Dangling pointer vulnerability or weakness.
Products Associated with CVE-2024-49016
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2024-49016 are published in these products:
Affected Versions
Microsoft SQL Server 2017 (GDR):- Version 14.0.0 and below 14.0.2070.1 is affected.
- Version 15.0.0 and below 15.0.2130.3 is affected.
- Version 13.0.0 and below 13.0.6455.2 is affected.
- Version 13.0.0 and below 13.0.7050.2 is affected.
- Version 14.0.0 and below 14.0.3485.1 is affected.
- Version 15.0.0 and below 15.0.4410.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.