Impact
A heap‑based buffer overflow in the SQL Server ODBC driver enables an unauthorized attacker to execute arbitrary code directly from a network connection. The flaw is due to the driver’s improper memory corruption vulnerability identified as CWE‑122.
Affected Systems
Affected systems include Microsoft Windows operating systems: Windows 10 releases from Version 1607 through 22H2, Windows 11 variants such as 23H2, 24H2, 25H2, 26H1, and Windows Server editions from 2012 through 2025. Each of these builds includes the vulnerable ODBC driver.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical, while the EPSS score of less than 1% indicates that automated exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector involves a network connection to the affected system, and the description suggests that no authentication is required to trigger the overflow, giving the attacker code execution capability.
OpenCVE Enrichment