Описание
Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
Меры по смягчению последствий
The following mitigating factors might be helpful in your situation:
The victim must have installed Microsoft OLE DB Provider for DB2 Server Version 7.0 for the target machine to be vulnerable.
FAQ
How could an attacker exploit this vulnerability?
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target machine if the victim connects to the attacker's malicious DB2 server and they execute a specially crafted query.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Host Integration Server 2020 | ||
| Microsoft OLE DB Provider for DB2 V7 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
8.8 High
CVSS3
Связанные уязвимости
Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
Уязвимость приложения-шлюза Microsoft Host Integration Server, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3