Impact
This vulnerability involves an improper handling of special elements in SQL commands, resulting in a SQL injection flaw that allows an attacker who already has local access to elevate privileges on the host system. The weakness is categorized as CWE-89. The impact is the ability to gain higher privileges locally, potentially enabling an attacker to access restricted data or compromise the database server.
Affected Systems
Affected are Microsoft SQL Server releases from version 2016 through 2025, including 2016 Service Pack 3 (GDR) and Azure Connect Feature Pack, 2017 CU 31 and GDR, 2019 CU 32 and GDR, 2022 GDR and CU 25, and 2025 CU 6 and GDR, all on x64-based systems.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while an EPSS score of less than 1% signals a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an attacker who already has some local access to the machine containing the SQL Server instance to exploit the SQL injection flaw and elevate privileges.
OpenCVE Enrichment