CVE-2024-21451

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 12, 2024
Updated: Apr 11, 2024
CWE ID 197

Summary

CVE-2024-21451 is a newly disclosed vulnerability affecting Microsoft ODBC (Open Database Connectivity) Driver. This issue permits an attacker to execute arbitrary code remotely by exploiting a vulnerability in the way the driver handles ODBC connections. Successful exploitation could lead to significant data loss or unauthorized system access. Users are strongly urged to apply the forthcoming Microsoft security patch as soon as it becomes available to mitigate this risk. Until then, it's recommended to restrict access to the affected systems and monitor them closely for suspicious activity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11

Affected Vendors

  • Microsoft