Impact
The vulnerability is an improper neutralization of special elements used in an SQL command, allowing an attacker with authorized access to inject malicious SQL code. This injection can elevate the attacker's privileges over the network, potentially granting higher database access rights and control. The weakness is a classic SQL Injection compromise (CWE‑89).
Affected Systems
Affected systems are Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), SQL Server 2019 (Cumulative Update 32 and GDR), SQL Server 2022 (Cumulative Update 26 and GDR), and SQL Server 2025 (Cumulative Update 8 and GDR) on x64-based platforms. All protected versions listed in the CNA data are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation data is currently lacking. The attack vector is inferred to be over the network because the vulnerability involves remote execution of SQL commands against the server. An attacker who already has some form of network access and sufficient permissions could use an SQL injection payload to elevate privileges, enabling further actions such as unauthorized data access or modification.
OpenCVE Enrichment