Impact
The vulnerability is a type‑confusion flaw in Microsoft SQL Server 2025. It allows an attacker who already has authorized access to the server to read data that the server does not intend to expose, effectively leaking confidential information across the network. The weakness, classified as CWE‑843, does not provide a path to alter data, execute arbitrary code, or impact availability.
Affected Systems
Microsoft SQL Server 2025 (CU 6) and Microsoft SQL Server 2025 for x64‑based systems (GDR) are the affected products. The CNA lists these two specific releases with no further version exclusions, meaning any instance of either release that has not been updated is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % shows that exploitation is unlikely in the wild. The vulnerability is not currently recorded in the CISA KEV catalog. An attacker must be authenticated against the database engine; there is no privilege escalation or code‑execution side‑channel. The attack vector is thus network‑based information disclosure through equivalent or higher‑privileged credentials.
OpenCVE Enrichment