This post has been republished via RSS; it originally appeared at: Microsoft Tech Community - Latest Blogs - .
We've released hotfix packages for the following drivers to address important security issues:
- Microsoft ODBC Driver 17.10.4 for SQL Server (release notes)
- Microsoft ODBC Driver 18.2.2 for SQL Server (release notes)
- Microsoft OLE DB Driver 18.6.6 for SQL Server (release notes)
- Microsoft OLE DB Driver 19.3.1 for SQL Server (release notes)
Related CVEs for these updates are the following:
- CVE-2023-29349 - Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
- CVE-2023-32028 - Microsoft OLE DB Remote Code Execution Vulnerability
- CVE-2023-32027 - Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-32026 - Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-32025 - Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-29356 - Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
All the issues involve a malicious server sending malicious data in order to compromise a client. These driver updates are included in SQL Server 2019 CU21 and SQL Server 2022 CU5. If you use the drivers in the context of either of those installs, those updates will update the drivers for you. If you have deployed the drivers as part of a standalone application, you may want to consider updating them. The vulnerabilities require a potential attacker to direct a connection to a malicious server, so if your scenario allows that, you should update.
Next steps
For Windows installations, you can directly download the Microsoft ODBC Driver 18 for SQL Server or the Microsoft ODBC Driver 17 for SQL Server.
Linux and macOS packages are also available and can be updated via package managers on most platforms. For installation details and manual instructions, see the online instructions for Linux or macOS.
Roadmap
We are committed to improving quality and bringing more feature support for connecting to SQL Server Azure SQL Database Azure SQL DW, and Azure SQL Managed Instance through regular driver releases. We invite you to explore the latest the Microsoft Data Platform has to offer via a trial of Microsoft Azure SQL Database or by evaluating Microsoft SQL Server.
David Engel
