Disclosure summary
CVE-2024-21907 addresses a mishandling of exceptional conditions vulnerability in Newtonsoft.Json before version 13.0.1. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition. The documented SQL Server updates incorporate updates in Newtonsoft.Json which address this vulnerability. Please see CVE-2024-21907 for more information.
Source-reported weakness categories
CWE-1395
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2025-Sep
Open original source · Updated Sep 09, 2025
VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | Microsoft SQL Server 2017 for x64-based Systems (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2019 for x64-based Systems (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2017 for x64-based Systems (CU 31) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2019 for x64-based Systems (CU 32) | (MSRC status code 3) |
Vendor remediation references
- 5065224 · build 14.0.2085.1 · product IDs 11478
- Vendor guidance · product IDs 11478
- 5065223 · build 15.0.2145.1 · product IDs 11821
- Vendor guidance · product IDs 11821
- 5065226 · build 13.0.6470.1 · product IDs 12048
- Vendor guidance · product IDs 12048
- 5065227 · build 13.0.7065.1 · product IDs 12053
- Vendor guidance · product IDs 12053
- 5065225 · build 14.0.3505.1 · product IDs 12145
- Vendor guidance · product IDs 12145
- 5065222 · build 15.0.4445.1 · product IDs 16785
- Vendor guidance · product IDs 16785
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2025-09-09T03:00:00-04:00
MODIFIED 2025-09-09T03:00:00-04:00
INGESTED 2026-10-08T12:45:42-04:00