Security Update for SQL Server 2014 Service Pack 2 GDR (KB4505217)
If you have a pop-up blocker enabled, the Download window might not open. To open the Download window, configure your pop-blocker to allow pop-ups for this Web site.
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions. An attacker who successfully exploited this vulnerability could execute code in the context of the SQL Server Database Engine service account. To exploit the vulnerability, an authenticated attacker would need to submit a specially crafted query to an affected SQL server. The security update addresses the vulnerability by modifying how the Microsoft SQL Server Database Engine handles the processing of functions.
Microsoft SQL Server 2014
KB article numbers:
This update has been replaced by the following updates:
This update replaces the following updates:
Security Update for SQL Server 2014 Service Pack 2 GDR (KB3194714)
Security Update for SQL Server 2014 Service Pack 2 GDR (KB4019093)
Security Update for SQL Server 2014 Service Pack 2 GDR (KB4057120)
There are no additional languages to select
Can request restart
May request user input:
Must be installed exclusively:
Requires network connectivity:
This software update can be removed via Add or Remove Programs in Control Panel.
Add to Basket
Remove from Basket