Impact
Improper neutralization of special elements in an SQL command (SQL injection, CWE-89) allows an authenticated attacker to elevate privileges over the network. When a user with authorized access can send commands to SQL Server, they can exploit this flaw to gain higher database privileges or alter the security state of the environment. The flaw is limited to authenticated users and does not affect all services, but any compromised or over‑privileged account can be abused for privilege escalation.
Affected Systems
Affected versions include Microsoft SQL Server 2016 Service Pack 3 (GDR) and the Azure Connect Feature Pack for 2016, Microsoft SQL Server 2017 Cumulative Update 31 and GDR, Microsoft SQL Server 2019 Cumulative Update 32 and GDR, Microsoft SQL Server 2022 GDR and Cumulative Update 25 for x64-based systems, and Microsoft SQL Server 2025 Cumulative Update 6 and GDR for x64-based systems.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA KEV. Because an attacker requires authenticated access, organizations that provide broad or privileged database accounts remain at risk. If exploited over the network, the flaw could allow the attacker to gain administrative privileges or otherwise change the security state of the database.
OpenCVE Enrichment