Impact
Deserialization of untrusted data in Microsoft SQL Server enables an attacker with the appropriate authorisation to run arbitrary code on the server via the network. The flaw allows a remote attacker to exploit the application by sending crafted payloads that the database engine deserialises, leading to full compromise of the SQL Server process. This constitutes a high‑severity vulnerability, evidenced by the CVSS score of 8.8, and could result in loss of confidentiality, integrity, and availability of the entire database system.
Affected Systems
The vulnerability affects Microsoft SQL Server 2025 in the Community Update 6 (CU 6) release and the 2025 for x64‑based Systems gradual daily release (GDR). Only the x64 edition is impacted, as indicated by the associated CPE string. Users running these specific releases should ensure they are not operating with the unpatched versions.
Risk and Exploitability
With an EPSS score of 1 %, the likelihood of exploitation in the wild is low but non‑zero, and the CVE is not currently listed in the CISA KEV catalog. The attack requires an authorised user or an attacker who can inject data into the database engine; it is therefore plausibly exploitable within a trusted network or application environment. Based on the description, the primary vector is remote network traffic directed at the SQL Server service where deserialization occurs. Continuous monitoring for abnormal deserialization attempts and limiting network exposure are prudent. The high CVSS indicates that successful exploitation would enable local privilege escalation and full control of the host.
OpenCVE Enrichment