Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-30077: Windows OLE Remote Code Execution Vulnerability

How could an attacker exploit this vulnerability?

An attacker could exploit the vulnerability by tricking an authenticated user (UI:R) into attempting to connect to a malicious SQL server database via a connection driver (for example: OLE DB or OLEDB as applicable). This could result in the database returning malicious data that could cause arbitrary code execution on the client.

Microsoft Security Response Center
#sql#vulnerability#windows#rce#auth#Microsoft WDAC OLE DB provider for SQL#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-43552: Windows Shell Remote Code Execution Vulnerability