« Volver al listado

Microsoft

Microsoft SQL Server 2017: vulnerabilidades y CVE

Microsoft SQL Server 2017 tiene 144 vulnerabilidades publicadas, 55 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE144
Últimos 12 meses55
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-1068Alta (8.8)57%⚠ Explotación activa15 jul 2019
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77488Media (5.5)0.40%—8 sept 2026
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
CVE-2026-77487Alta (8.8)0.78%—8 sept 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77486Alta (8.8)0.82%—8 sept 2026
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77485Alta (7)0.26%—8 sept 2026
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-77483Alta (8.8)0.78%—8 sept 2026
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77482Alta (8.8)0.82%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77481Alta (8.8)0.91%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-77480Alta (8.8)0.78%—8 sept 2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-73028Alta (8.8)0.78%—8 sept 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-68787Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
CVE-2026-68786Alta (8.8)0.91%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-68785Media (4.9)1.1%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-68784Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68781Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68780Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68779Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68778Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68777Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68776Media (6.5)1.00%—8 sept 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68775Alta (8.8)0.91%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67648Media (6.5)1.00%—8 sept 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67645Media (6.5)1.00%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67639Alta (8.8)0.91%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67633Media (6.5)1.1%—8 sept 2026
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
CVE-2026-67631Crítica (9.8)0.97%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67393Media (6.5)1.00%—8 sept 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67390Media (6.5)1.00%—8 sept 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67388Alta (8.8)0.91%—8 sept 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67386Media (6.5)1.00%—8 sept 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67385Alta (8.8)0.91%—8 sept 2026
Use after free in SQL Server allows an authorized attacker to execute code over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services20
  2. T1059 Command and Scripting Interpreter15
  3. T1068 Exploitation for Privilege Escalation12
  4. T1203 Exploitation for Client Execution3
  5. T1190 Exploit Public-Facing Application2
  6. T1059.001 PowerShell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft