Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinternet-facing-service-vulnerability

Microsoft Patched Multiple SQL Server Client and Component Flaws

Updated 28d agoFirst seen May 25, 202649 sources

Microsoft disclosed a broad set of vulnerabilities affecting the SQL Server ecosystem, including remote code execution, elevation of privilege, and information disclosure issues across SQL Server Native Client, Microsoft ODBC Driver for SQL Server, core Microsoft SQL Server components, and Microsoft.SqlServer.XEvent.Configuration.dll. The largest group of advisories covered SQL Server Native Client RCE flaws, including CVE-2024-38255, CVE-2024-43459, CVE-2024-43462, CVE-2024-48993, CVE-2024-48995, CVE-2024-48996, CVE-2024-48997, CVE-2024-48998, CVE-2024-48999, CVE-2024-49000, CVE-2024-49004, CVE-2024-49005, and CVE-2024-49007. Microsoft also listed CVE-2024-49043 as an RCE flaw in Microsoft.SqlServer.XEvent.Configuration.dll and earlier ODBC driver RCE bugs CVE-2023-36730 and CVE-2023-36785.

Additional SQL Server issues included Native Scoring RCE vulnerabilities CVE-2024-26186 and CVE-2024-37338, Native Scoring information disclosure flaws CVE-2024-37342 and CVE-2024-37966, SQL Server elevation of privilege bugs CVE-2024-37965, CVE-2024-37341, CVE-2024-37980, and CVE-2026-26116, plus a general SQL Server information disclosure issue tracked as CVE-2024-43474. The disclosures show Microsoft addressing repeated attack surface in SQL Server connectivity layers and supporting components, underscoring the need for organizations running SQL Server clients, drivers, and related libraries to prioritize vendor updates across both server-side and workstation-deployed software.

Share:
Microsoft Patched Multiple SQL Server Client and Component Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

18 events from the most recent confirmed update back to the earliest known activity.

18 EVENTS
Apr 14, 20262mo ago

Microsoft discloses SQL Server RCE vulnerability CVE-2026-33120

Microsoft published a Security Update Guide entry for CVE-2026-33120, a remote code execution vulnerability affecting Microsoft SQL Server. The advisory included guidance for applying the appropriate security updates across supported SQL Server versions and servicing tracks.

CVE-2026-33120 - Security Update Guide - Microsoft - Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft publishes SQL Server elevation of privilege flaw CVE-2026-32176

Microsoft released a Security Update Guide entry for CVE-2026-32176, an elevation of privilege vulnerability affecting SQL Server. The advisory was published as part of Microsoft's 2026-04-14 security updates.

CVE-2026-32176 - Security Update Guide - Microsoft - SQL Server Elevation of Privilege Vulnerability

Microsoft publishes SQL Server elevation of privilege flaw CVE-2026-32167

Microsoft released a Security Update Guide entry for CVE-2026-32167, an elevation of privilege vulnerability affecting SQL Server.

CVE-2026-32167 - Security Update Guide - Microsoft - SQL Server Elevation of Privilege Vulnerability
Mar 10, 20264mo ago

Microsoft publishes SQL Server elevation of privilege flaw CVE-2026-26116

Microsoft released a Security Update Guide entry for CVE-2026-26116, an elevation of privilege vulnerability affecting SQL Server.

Sep 9, 202510mo ago

Microsoft publishes SQL Server elevation of privilege flaw CVE-2025-55227

Microsoft released a Security Update Guide entry for CVE-2025-55227, an elevation of privilege vulnerability affecting Microsoft SQL Server. The advisory was published on 2025-09-09.

CVE-2025-55227 - Security Update Guide - Microsoft - Microsoft SQL Server Elevation of Privilege Vulnerability

Microsoft discloses SQL Server information disclosure flaw CVE-2025-47997

Microsoft published a Security Update Guide entry for CVE-2025-47997, an information disclosure vulnerability affecting Microsoft SQL Server. The advisory was released on 2025-09-09.

CVE-2025-47997 - Security Update Guide - Microsoft - Microsoft SQL Server Information Disclosure Vulnerability
Jul 8, 20251y ago

Microsoft discloses SQL Server information disclosure flaw CVE-2025-49719

Microsoft published a Security Update Guide entry for CVE-2025-49719, an information disclosure vulnerability affecting Microsoft SQL Server. The advisory was released on 2025-07-08.

CVE-2025-49719 - Security Update Guide - Microsoft - Microsoft SQL Server Information Disclosure Vulnerability

Microsoft discloses SQL Server RCE vulnerability CVE-2025-49717

Microsoft published a Security Update Guide entry for CVE-2025-49717, a remote code execution vulnerability affecting Microsoft SQL Server. The advisory was released on 2025-07-08.

CVE-2025-49717 - Security Update Guide - Microsoft - Microsoft SQL Server Remote Code Execution Vulnerability
Nov 12, 20242y ago

Microsoft discloses XEvent.Configuration.dll RCE vulnerability

Microsoft published Security Update Guide entry CVE-2024-49043, a remote code execution vulnerability in Microsoft.SqlServer.XEvent.Configuration.dll, as part of its November 2024 releases.

Microsoft issues broad SQL Server Native Client RCE fixes

Microsoft published a large set of Security Update Guide entries for SQL Server Native Client remote code execution vulnerabilities, including CVE-2024-38255, CVE-2024-43459, CVE-2024-43462, CVE-2024-48993, CVE-2024-48995, CVE-2024-48996, CVE-2024-48997, CVE-2024-48998, CVE-2024-48999, CVE-2024-49000, CVE-2024-49004, CVE-2024-49005, and CVE-2024-49007.

Sep 10, 20242y ago

Microsoft discloses SQL Server Native Scoring RCE flaw CVE-2024-37340

Microsoft published a Security Update Guide entry for CVE-2024-37340, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.

CVE-2024-37340 - Security Update Guide - Microsoft - Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Microsoft discloses SQL Server Native Scoring RCE flaw CVE-2024-37339

Microsoft published a Security Update Guide entry for CVE-2024-37339, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.

CVE-2024-37339 - Security Update Guide - Microsoft - Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Microsoft discloses SQL Server Native Scoring RCE flaw CVE-2024-37335

Microsoft published a Security Update Guide entry for CVE-2024-37335, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.

CVE-2024-37335 - Security Update Guide - Microsoft - Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Microsoft discloses SQL Server Native Scoring RCE flaw CVE-2024-26191

Microsoft published a Security Update Guide entry for CVE-2024-26191, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.

CVE-2024-26191 - Security Update Guide - Microsoft - Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Microsoft releases September 2024 SQL Server security updates

Microsoft published multiple SQL Server-related advisories covering remote code execution, elevation of privilege, and information disclosure issues, including CVE-2024-26186, CVE-2024-37338, CVE-2024-37341, CVE-2024-37342, CVE-2024-37965, CVE-2024-37966, CVE-2024-37980, and CVE-2024-43474.

Oct 10, 20233y ago

Microsoft discloses SQL Server denial of service flaw CVE-2023-36728

Microsoft published a Security Update Guide entry for CVE-2023-36728, a denial of service vulnerability affecting Microsoft SQL Server. The advisory was released on 2023-10-10.

CVE-2023-36728 - Security Update Guide - Microsoft - Microsoft SQL Server Denial of Service Vulnerability

Microsoft discloses SQL OLE DB RCE vulnerability CVE-2023-36417

Microsoft published a Security Update Guide entry for CVE-2023-36417, a remote code execution vulnerability affecting Microsoft SQL OLE DB. The advisory was released on 2023-10-10.

CVE-2023-36417 - Security Update Guide - Microsoft - Microsoft SQL OLE DB Remote Code Execution Vulnerability

Microsoft patches ODBC Driver for SQL Server RCE flaws

Microsoft published Security Update Guide entries for CVE-2023-36730 and CVE-2023-36785, both remote code execution vulnerabilities affecting the Microsoft ODBC Driver for SQL Server.

SOURCE COVERAGE

Sources

49 references tracked. Mallory keeps watching after this page renders.

49 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.