← back
CVE-2024-26162

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVSS 8.8 HIGHEPSS 2.0%CWE-681
In short

The Microsoft ODBC Driver contains a flaw that allows attackers to execute arbitrary code remotely on systems using the affected driver. An attacker can exploit this vulnerability by sending specially crafted requests to a system running the vulnerable ODBC Driver, potentially gaining full control of the affected machine.

Technical detail

CWE-681 vulnerability in Microsoft ODBC Driver permits remote code execution through malformed input handling. The attack vector requires network accessibility to the ODBC service; exploitation leads to arbitrary code execution with the privileges of the ODBC Driver process, affecting confidentiality, integrity, and availability of affected systems.

Summary generated and translated by AI from the official description.
Microsoft ODBC Driver Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →