Impact
The vulnerability originates from insufficient granularity of access control in Microsoft SQL Server, allowing an attacker who already has some level of authorized access to raise their privileges over the network. This flaw falls under CWE‑1220 – Weak Access Control. If successfully exploited, the attacker could gain higher level permissions on the database engine, enabling unauthorized execution of privileged commands, data modification or extraction, and potentially compromising other connected systems.
Affected Systems
Affected products include Microsoft SQL Server 2017 updated to CU 31 or the GDR release, Microsoft SQL Server 2019 updated to CU 32 or the GDR release, Microsoft SQL Server 2022 updated to CU 26 or the GDR release, and Microsoft SQL Server 2025 updated to CU 8 or the GDR release for x64‑based systems. All these versions share the same access‑control implementation that lacks fine‑grained permission enforcement.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity flaw. Because the exploit requires an attacker to be already authenticated and authorized to an account with some database access, the attack surface is limited to insider or compromised user accounts. The EPSS score is not available, so current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the possibility of privilege escalation in a networked database environment poses a significant risk if internal attackers abuse their foothold.
OpenCVE Enrichment