Searching
..

Click anywhere to stop

KLA11168
Multiple vulnerabilities in Microsoft SQL Server

Обновлено: 03/06/2020
Дата обнаружения
03/01/2018
Уровень угрозы
High
Описание

Multiple information disclosure vulnerabilities have been found in Microsoft SQL Server. Malicious user can exploit these vulnerabilities to obtain sensitive information. These vulnerabilities can be exploited remotelly via speculative execution side-channel attack to obtain sensetive information.

All Kaspersky Lab business and consumer products are compatible with the update. Our database update on 28th December enables the compatibility flag, recommended by Microsoft, to allow devices to apply the update from 3rd January.Further details of Kaspersky Lab compatibility with Microsoft security updates are on our Support page.Our recommendation remains that for optimum protection against vulnerabilities, software and operating system updates should be installed as soon as possible.More about the CPU vulnerabilities can be found on the Kaspersky Lab blog here and on the announcement website here.

Пораженные продукты

Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (CU)
Microsoft SQL Server 2016 for x64-based Systems Service Pack 1
Microsoft SQL Server 2017 for x64-based Systems (CU)
Microsoft SQL Server 2017 for x64-based Systems

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
ADV180002
Связанные продукты
Microsoft SQL Server