CVE-2024-37980
Microsoft SQL Server Elevation of Privilege Vulnerability
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 1.36%
- CWE
- CWE-269
- Published
- 2024-09-10
- Last modified
- 2026-08-10
Affected products
- Microsoft Microsoft SQL Server 2017 (GDR)
- Microsoft Microsoft SQL Server 2019 (GDR)
- Microsoft Microsoft SQL Server 2016 Service Pack 3 (GDR)
- Microsoft Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack
- Microsoft Microsoft SQL Server 2017 (CU 31)
- Microsoft Microsoft SQL Server 2022 (GDR)
- Microsoft Microsoft SQL Server 2019 (CU 28)
- Microsoft Microsoft SQL Server 2022 for (CU 14)
Weakness type
Related vulnerabilities
- CVE-2026-84869 — ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
- CVE-2026-79090 — Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci
- CVE-2026-79226 — Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
- CVE-2026-78999 — Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co
- CVE-2026-73269 — Cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates clusterrolebinding granting cluster-wide secrets access to namespace-local sa
- CVE-2026-9193 — Privilege escalation in Progress MarkLogic Server Hadoop integration
- CVE-2026-8709 — Privilege escalation in Progress MarkLogic Server REST document patch operation
- CVE-2026-7329 — Privilege escalation in Progress MarkLogic Server REST query interfaces