Impact
A stack‑based buffer overflow in Microsoft Fabric Data Warehouse enables a remote attacker with authorized access to execute arbitrary code over the network. The flaw occurs when the system processes input that exceeds the allocated stack buffer, allowing memory corruption and arbitrary code execution. It is a classic stack overflow defect (CWE-121).
Affected Systems
This vulnerability affects Microsoft Service Fabric’s Fabric Data Warehouse component. No specific version information is listed, so any installation of the Fabric Data Warehouse may be impacted until updated.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is below 1% suggesting a low probability of being exploited in the wild, and it is not included in the CISA KEV catalog. Attack vectors are likely through network communication with the Fabric Data Warehouse service, and exploitation requires approved credentials or privileged access as implied by the description.
OpenCVE Enrichment