Skip to main content

Upgrade Microsoft OLE DB Driver for SQL Server to Avoid Remote Code Execution Vulnerability CVE-2023-38169 - Knowledgebase / Lasernet / Lasernet General Information - Formpipe Support Portal

Upgrade Microsoft OLE DB Driver for SQL Server to Avoid Remote Code Execution Vulnerability CVE-2023-38169

Authors list

The Lasernet Server and Lasernet Meta installers install Microsoft OLE DB Driver for SQL Server. However, Lasernet 9.15.5 (and earlier) and Lasernet 10.5.2 (and earlier) install a version of the driver (18.3.0) that has the following vulnerability: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38169

This vulnerability is resolved in Microsoft OLE DB Driver for SQL Server 18.6.7.

To ensure that this vulnerability is not present on Lasernet servers (Server app) or clients (Meta app), use one of the following methods to upgrade the installed driver to version 18.6.7:

Warning

Do not install version 19 of Microsoft OLE DB Driver for SQL Server. The first version of Lasernet that will support version 19 of the driver will be Lasernet 11.


Helpful Unhelpful

Add a comment

Please log in or register to submit a comment.

Need a password reminder?

Share