Impact
A buffer over-read in Microsoft SQL Server 2025 exposes memory content to an attacker who already has authorized access. The vulnerability allows the attacker to read data beyond the boundaries of a buffer and send the illegitimate data across the network, potentially revealing sensitive information that should remain confidential. The weakness is identified as a buffer over-read (CWE‑126).
Affected Systems
Microsoft SQL Server 2025 (CU 6) and Microsoft SQL Server 2025 for x64‑based Systems (GDR) are affected. Instances that have not applied the latest cumulative update that addresses the over‑read condition remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker possess legitimate credentials or otherwise authorized access to the SQL Server instance, and the attack vector is over the network. Given these prerequisites, the primary risk is unauthorized data exposure rather than disruption or corruption of database contents.
OpenCVE Enrichment