Microsoft SQL Server Vulnerability CVE-2019-1068: Early Warning
- Severity
- HIGH
- Affected component
- microsoft sql server (nuget)
- Patched version
- Not yet available
An early warning has been issued for a high-severity remote code execution vulnerability in Microsoft SQL Server. This vulnerability could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068 to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability is reportedly being exploited in the wild. The vulnerability affects Microsoft SQL Server, but no authoritative version range has been published yet. Users are advised to upgrade to the latest version of Microsoft SQL Server and apply necessary patches as soon as they become available.
CISA's addition of this vulnerability to the KEV catalog indicates that it is actively being exploited. Organizations using Microsoft SQL Server should immediately assess their exposure and take appropriate mitigation steps. The vulnerability allows remote code execution, making it a critical issue for affected systems.
What to do about it
- Upgrade to the latest version of Microsoft SQL Server.
- Apply all necessary patches as soon as they become available.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
- Consider implementing additional security measures to protect your SQL Server instances.
- Regularly review and update your security policies to address new threats.
How 0Day would have caught this
microsoft sql server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Microsoft SQL Server, you may be affected. No authoritative version range has been published yet, so it is recommended to upgrade to the latest version and apply patches as soon as they become available.
What should I do right now?
Upgrade to the latest version of Microsoft SQL Server and apply all necessary patches. Monitor the primary sources for updates on the vulnerability and any official fixes.
Has this been exploited in the wild?
Yes, this vulnerability is reportedly being exploited in the wild.