Impact
Deserialization of untrusted data during certain SQL Server operations allows an authorized attacker to execute arbitrary code on a networked host. The flaw, identified by CWE-502, permits the crafting of malicious payloads that bypass normal input validation. Based on the description, it is inferred that the attacker must first obtain legitimate database credentials or otherwise be authenticated to supply the dangerous data, after which remote code execution follows.
Affected Systems
Affected versions include Microsoft SQL Server 2016 Service Pack 3 and its Azure Connect Feature Pack, SQL Server 2017 CU 31 and the corresponding GDR, SQL Server 2019 CU 32 and the corresponding GDR, SQL Server 2022 GDR and the CU 25 build for 64‑bit systems, and SQL Server 2025 CU 6 and the corresponding GDR for 64‑bit systems. All impacted releases run on x64 architecture and share the same deserialization defect.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high‑severity, and the EPSS score of 1 % indicates that exploitation attempts are uncommon but possible. Because it is not listed in the CISA KEV catalog, no publicly confirmed exploit exists, yet an authenticated attacker could achieve full remote control of the SQL Server instance and potentially compromise the underlying operating system. The risk profile remains high, warranting immediate attention.
OpenCVE Enrichment