1.1 Ensure Latest SQL Server Service Packs and Hotfixes are Installed

Information

SQL Server patches contain program updates that fix security and product functionality issues found in the software. These patches can be installed with a hotfix which is a single patch, a cumulative update which is a small group of patches or a service pack which is a large collection of patches. The SQL Server version and patch levels should be the most recent compatible with the organizations' operational needs.

Rationale:

Using the most recent SQL Server software, along with all applicable patches can help limit the possibilities for vulnerabilities in the software. The installation version and/or patches applied during setup should be established according to the needs of the organization.

NOTE: Update SERVICE_PACK and VERSION to the appropriate value for the local environment.

Solution

Identify the current version and patch level of your SQL Server instances and ensure they contain the latest security fixes. Make sure to test these fixes in your test environments before updating production instances.

The most recent SQL Server patches can be found here:

Hotfixes and Cumulative updates: https://docs.microsoft.com/en-us/sql/database-engine/install-windows/latest-updates-for-microsoft-sql-server?view=sql-server-ver15&viewFallbackFrom=sql-server-previousversions

Service Packs: https://support.microsoft.com/en-us/help/2755533/how-to-obtain-the-latest-service-pack-for-sql-server-2012

Default Value:

Service packs and patches are not installed by default.

References:

https://support.microsoft.com/en-us/help/2755533/how-to-obtain-the-latest-service-pack-for-sql-server-2012

See Also

https://workbench.cisecurity.org/files/2837

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), CSCv6|4, CSCv7|2.2

Plugin: MS_SQLDB

Control ID: 6db2c6ebb120789c796781a4bd3f7654b06bbb1033c1779d8b056d54e2d56759