📦 Sql Server 2017

by Microsoft

🔍 What is Sql Server 2017?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59499

HIGH CVSS 8.8 Nov 11, 2025

This SQL injection vulnerability in Microsoft SQL Server allows authenticated attackers to execute arbitrary SQL commands, potentially leading to privilege escalation. It affects SQL Server instances ...

CVE-2025-55227

HIGH CVSS 8.8 Sep 9, 2025

This command injection vulnerability in SQL Server allows authenticated attackers to execute arbitrary commands on the database server, potentially gaining full system control. It affects SQL Server i...

CVE-2025-49759

HIGH CVSS 8.8 Aug 12, 2025

This SQL injection vulnerability in Microsoft SQL Server allows authenticated attackers to execute arbitrary SQL commands, potentially leading to privilege escalation. It affects SQL Server instances ...

CVE-2025-24999

HIGH CVSS 8.8 Aug 12, 2025

This vulnerability allows an authenticated attacker with existing SQL Server access to elevate privileges over the network, potentially gaining administrative control. It affects Microsoft SQL Server ...

CVE-2024-49021

HIGH CVSS 7.8 Nov 12, 2024

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SQL Server instances by exploiting a use-after-free memory corruption flaw. It affects SQL Server installations with n...

CVE-2024-49016

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems running vulnerable versio...

CVE-2024-49018

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems running vulnerable versio...

CVE-2024-49012

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected server. It affects systems running vulnerable vers...

CVE-2024-49014

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems running vulnerable versio...

CVE-2024-49008

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects systems running vulnerable vers...

CVE-2024-49010

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects systems running vulnerable vers...

CVE-2024-49002

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects systems running vulnerable vers...

CVE-2024-49004

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted network packets. It affects systems running vulnerable versions of SQL Ser...

CVE-2024-49006

HIGH CVSS 8.8 Nov 12, 2024

This vulnerability in SQL Server Native Client allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects systems running vulnerable vers...

CVE-2024-37965

HIGH CVSS 8.8 Sep 10, 2024

This CVE describes an elevation of privilege vulnerability in Microsoft SQL Server where an authenticated attacker could execute arbitrary code with elevated privileges. It affects SQL Server instance...

CVE-2024-37980

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server allows authenticated attackers to elevate their privileges within the database system. Attackers could gain administrative control over SQL Server instances,...

CVE-2024-37339

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server's Native Scoring component allows authenticated attackers to execute arbitrary code remotely. It affects SQL Server instances with the Native Scoring feature...

CVE-2024-37341

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server allows authenticated attackers to execute arbitrary code with elevated privileges, potentially gaining full control of the database server. It affects SQL Se...

CVE-2024-37337

HIGH CVSS 7.1 Sep 10, 2024

This vulnerability in Microsoft SQL Server Native Scoring allows an authenticated attacker to read sensitive information from memory. It affects SQL Server instances where the Native Scoring feature i...

CVE-2024-26186

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server Native Scoring allows remote attackers to execute arbitrary code on affected systems. Attackers can exploit this use-after-free vulnerability to gain SYSTEM ...

CVE-2024-38087

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using thi...

CVE-2024-37332

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-37328

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-37330

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-37321

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using the...

CVE-2024-37323

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provider. Attackers can exploit this integer overflow vul...

CVE-2024-37326

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provider. Attackers can exploit this heap-based buffer ov...

CVE-2024-35271

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects applications us...

CVE-2024-37319

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects systems running...

CVE-2024-21449

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provider. Attackers can exploit this heap-based buffer ov...

CVE-2024-21414

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using thi...

CVE-2024-21425

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted queries. It affects systems running vu...

CVE-2024-21333

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using the...

CVE-2024-21373

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using the...

CVE-2024-21308

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using thi...

CVE-2024-21331

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems running v...

CVE-2024-20701

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...