Description
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer over-read in Microsoft SQL Server 2025 exposes memory content to an attacker who already has authorized access. The vulnerability allows the attacker to read data beyond the boundaries of a buffer and send the illegitimate data across the network, potentially revealing sensitive information that should remain confidential. The weakness is identified as a buffer over-read (CWE‑126).

Affected Systems

Microsoft SQL Server 2025 (CU 6) and Microsoft SQL Server 2025 for x64‑based Systems (GDR) are affected. Instances that have not applied the latest cumulative update that addresses the over‑read condition remain vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker possess legitimate credentials or otherwise authorized access to the SQL Server instance, and the attack vector is over the network. Given these prerequisites, the primary risk is unauthorized data exposure rather than disruption or corruption of database contents.

Generated by OpenCVE AI on July 31, 2026 at 06:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest cumulative update or patch for Microsoft SQL Server 2025 from the official Microsoft update center. This patch resolves the buffer over-read condition and restores proper bounds checking.
  • Configure the SQL Server instance to accept connections only from trusted hosts and networks, applying strict firewall rules and network segmentation to limit exposure of vulnerable services.
  • Apply least privilege principles to all SQL Server accounts and regularly review permissions, ensuring that only necessary users have the privileges required for their tasks. Also monitor server logs for unusually large data reads or anomalous memory usage that could indicate an attempt to exploit the vulnerability.

Generated by OpenCVE AI on July 31, 2026 at 06:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 15 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2025
Weaknesses CWE-126
CPEs cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2025 (cu 2) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:57:27.893Z

Reserved: 2026-06-04T18:59:17.978Z

Link: CVE-2026-50468

cve-icon Vulnrichment

Updated: 2026-07-14T18:32:06.399Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:45:03Z

Weaknesses