Impact
The vulnerability is caused by improper privilege management in Microsoft SQL Server, allowing an attacker who already has authenticated access to the server to gain higher privileges over a network.
Affected Systems
Affected products include Microsoft SQL Server 2017 cumulative update 31 and the guaranteed delivery release, Microsoft SQL Server 2019 cumulative update 32 and the guaranteed delivery release, Microsoft SQL Server 2022 cumulative update 26 and the guaranteed delivery release, and Microsoft SQL Server 2025 cumulative update 8 and the guaranteed delivery release for x64‑based systems.
Risk and Exploitability
The CVSS base score of 8.8 classifies this issue as high severity. No EPSS score is available, so the current exploit probability is unknown; however, the vulnerability does not appear in the CISA KEV catalog, indicating no known active exploitation. The flaw requires an attacker to already possess authenticated access to a SQL Server instance, limiting the initial attack surface to environments where credentials are compromised or misused. Once that prerequisite is met, the attacker can elevate privileges, thereby compromising the security posture of affected databases.
OpenCVE Enrichment