Impact
This vulnerability involves an improper neutralization of special elements in SQL commands, resulting in a SQL injection flaw that allows an authorized attacker to elevate privileges over a network. The weakness is categorized as CWE-89. The impact is the ability to gain higher privileges, potentially enabling an attacker to access restricted data or compromise the database server.
Affected Systems
Affected are Microsoft SQL Server releases from version 2016 through 2025, including 2016 Service Pack 3 (GDR) and Azure Connect Feature Pack, 2017 CU 31 and GDR, 2019 CU 32 and GDR, 2022 GDR and CU 25, and 2025 CU 6 and GDR, all on x64-based systems.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% signals a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based, requiring an authorized attacker who can connect to the SQL Server instance over the network to exploit the SQL injection flaw and elevate privileges.
OpenCVE Enrichment