Description
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Unchanged
RL
O
RC
Changed
Affected products
- Microsoft / Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack13.0.0 – 13.0.7050.2
- Microsoft / Microsoft SQL Server 2016 Service Pack 3 (GDR)13.0.0 – 13.0.6455.2
- Microsoft / Microsoft SQL Server 2017 (CU 31)14.0.0 – 14.0.3485.1
- Microsoft / Microsoft SQL Server 2017 (GDR)14.0.0 – 14.0.2070.1
- Microsoft / Microsoft SQL Server 2019 (CU 29)15.0.0 – 15.0.4410.1
- Microsoft / Microsoft SQL Server 2019 (GDR)15.0.0 – 15.0.2130.3
- Microsoft / Microsoft SQL Server 2022 for (CU 15)16.0.0 – 16.0.4155.4
- Microsoft / Microsoft SQL Server 2022 (GDR)16.0.0 – 16.0.1135.2