Skip to main content

Upgrade Microsoft OLE DB Driver for SQL Server to Avoid Remote Code Execution Vulnerability CVE-2023-38169 - Knowledgebase / Lasernet / Lasernet General Information - Formpipe Support Portal

Upgrade Microsoft OLE DB Driver for SQL Server to Avoid Remote Code Execution Vulnerability CVE-2023-38169

Authors list

The Lasernet Server and Lasernet Meta installers install Microsoft OLE DB Driver for SQL Server. However, Lasernet 9.15.5 (and earlier) and Lasernet 10.5.2 (and earlier) install a version of the driver (18.3.0) that has the following vulnerability: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38169

This vulnerability is resolved in Microsoft OLE DB Driver for SQL Server 18.6.7.

To ensure that this vulnerability is not present on Lasernet servers (Server app) or clients (Meta app), use one of the following methods to upgrade the installed driver to version 18.6.7:

Warning

Do not install version 19 of Microsoft OLE DB Driver for SQL Server.


Helpful Unhelpful

Add a comment

Please log in or register to submit a comment.

Need a password reminder?

Share