Oracle’s April 2017 Critical Patch Update addressed CVE-2017-3599, a remotely exploitable, pre-authentication denial-of-service vulnerability in MySQL. An unauthenticated attacker could send crafted network traffic to an exposed MySQL service and cause it to become unavailable, affecting database-backed applications and dependent business services.
Organizations running affected Oracle MySQL deployments should apply the relevant Oracle CPU updates, prioritize internet- or partner-accessible database servers, and restrict MySQL network exposure to authorized hosts. Security teams should also monitor for abnormal or malformed connection activity and validate service availability after patching.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Oracle issued its Critical Patch Update Advisory for April 2017.
SECFORCE documented CVE-2017-3599, describing a pre-authentication remote denial-of-service issue affecting MySQL.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.