Description
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Microsoft SQL Server enables an attacker with the appropriate authorisation to run arbitrary code on the server via the network. The flaw allows a remote attacker to exploit the application by sending crafted payloads that the database engine deserialises, leading to full compromise of the SQL Server process. This constitutes a high‑severity vulnerability, evidenced by the CVSS score of 8.8, and could result in loss of confidentiality, integrity, and availability of the entire database system.

Affected Systems

The vulnerability affects Microsoft SQL Server 2025 in the Community Update 6 (CU 6) release and the 2025 for x64‑based Systems gradual daily release (GDR). Only the x64 edition is impacted, as indicated by the associated CPE string. Users running these specific releases should ensure they are not operating with the unpatched versions.

Risk and Exploitability

With an EPSS score of 1 %, the likelihood of exploitation in the wild is low but non‑zero, and the CVE is not currently listed in the CISA KEV catalog. The attack requires an authorised user or an attacker who can inject data into the database engine; it is therefore plausibly exploitable within a trusted network or application environment. Based on the description, the primary vector is remote network traffic directed at the SQL Server service where deserialization occurs. Continuous monitoring for abnormal deserialization attempts and limiting network exposure are prudent. The high CVSS indicates that successful exploitation would enable local privilege escalation and full control of the host.

Generated by OpenCVE AI on July 31, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update for Microsoft SQL Server 2025 that contains the fix for CVE‑2026‑54117.
  • Restart the SQL Server service after the update to load the corrected binaries.
  • If the patch cannot be applied immediately, isolate the server from untrusted networks, enforce strict authentication and least‑ accounts, and restrict inbound traffic to only necessary ports to minimise the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2025
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2025 (cu 2) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:41.965Z

Reserved: 2026-06-11T20:33:37.835Z

Link: CVE-2026-54117

cve-icon Vulnrichment

Updated: 2026-07-14T18:06:15.979Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data