KLA11517
ACE vulnerability in Microsoft SQL Server

Updated: 06/03/2020
Detect date
?
07/09/2019
Severity
?
High
Description

Remote code execution vulnerability was found in Microsoft SQL Server. Malicious users can exploit this vulnerability to execute arbitrary code.

Affected products

Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU+GDR)
Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)
Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (CU+GDR)
Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU+GDR)
Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)
Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU+GDR)
Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)
Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
Microsoft SQL Server 2017 for x64-based Systems (GDR)
Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (CU+GDR)
Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)
Microsoft SQL Server 2017 for x64-based Systems (CU+GDR)
Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (CU+GDR)
Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2019-1068

Impacts
?
ACE 
[?]
Related products
Microsoft SQL Server
CVE-IDS
?
Microsoft official advisories
Microsoft Security Update Guide
KB list

4505217
4505220
4505219
4505221
4505222
4505419
4505225
4505218
4505422
4505224

Find out the statistics of the vulnerabilities spreading in your region