Impact
This vulnerability is an improper neutralization of special elements in output that is subsequently consumed by a downstream component. The flaw enables an attacker who can influence that output to inject malicious content, resulting in elevation of privileges on the target SQL Server. The impact manifests as the attacker gaining higher-level permissions than intended.
Affected Systems
The affected software is Microsoft SQL Server Management Studio version 22. Only this specific product and version are mentioned as vulnerable; other versions of SQL Server Management Studio are not listed as affected.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity, emphasizing the high potential for privilege escalation. No EPSS score is available, so the current exploitation probability is unknown, but the absence of a KEV listing does not negate the risk. Given the network‑based nature implied by the ability to deliver the exploited output over a network, the likely attack vector is remote exploitation from an application or service that interacts with the vulnerable component.
OpenCVE Enrichment