CVE-2019-1068
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 26, 2026
- US federal agencies must remediate it by Aug 29, 2026 (BOD 22-01)
- First attack observed 1877 days after disclosure
- Used in ransomware campaigns
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Nov 1, 2024 Sep 4, 2024
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| microsoft | sql server | 2014 |
| microsoft | sql server 2016 | < 13.0.4259.0 |
| microsoft | sql server 2017 | < 14.0.2027.2 |
Related articles
VulnerabilitiesAmazon Kiro: a prompt injection exfiltrates data from the workspace with a single message
Researchers reveal a prompt injection flaw in Amazon Kiro that exfiltrates workspace data via a single message. Affects IDE versions, patched in update.
VulnerabilitiesZBT: Two New Factory Implants in Chinese Routers Expose Remote Root Access
On August 28, 2026, The Hacker News confirmed through the IEEE registered MAC prefix database that the blocks 78:A3:51 and F8:5E:3C belong to Shenzhen
APTAn ownCloud flaw allowed theft of Philippine nuclear data: CISA adds it to KEV
On August 27, 2026, CISA added three new vulnerabilities to the Known Exploited Vulnerabilities KEV catalog. The most severe is CVE-2023-49105, an
This product uses the NVD API but is not endorsed or certified by the NVD.