Impact
The flaw in Microsoft SQL Server originates from external manipulation of file names or paths that the engine processes, a condition classified as CWE‑73. An attacker who has legitimate local user rights can supply a crafted file name or path, causing the server to treat that input as a higher‑privileged request and thereby elevate the attacker’s privileges to that of a higher‑level account. This privilege escalation can enable the attacker to execute arbitrary code, access or modify databases, and compromise data confidentiality, integrity, and availability.
Affected Systems
Affected products include Microsoft SQL Server 2016 Service Pack 3 and its GDR, the 2016 Service Pack 3 Azure Connect Feature Pack, SQL Server 2017 CU 31 and its GDR, SQL Server 2019 CU 32 and its GDR, SQL Server 2022 GDR and CU 25, and SQL Server 2025 CU 6 and its GDR – all 64‑bit Windows editions. The vulnerability exists in components that process file name or path input across these releases.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1 % indicates a low probability of widespread exploitation; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local authorized access and the ability to supply a crafted file name or path, indicating that the attack vector is local privilege escalation rather than remote. Attack success depends on the attacker’s ability to influence the server’s file handling logic.
OpenCVE Enrichment