Impact
An improper link resolution before file access (link following) in Microsoft SQL Server allows an authorized attacker to elevate privileges over a network. The flaw permits a user with sufficient permissions within the database environment to gain higher-level rights on the SQL Server host, potentially enabling full control over the database, unauthorized data exfiltration, or system compromise. The vulnerability is classified as CWE‑59, reflecting a flaw that permits directory traversal or symbolic link attacks. Based on the description, it is inferred that an attacker who already has authorized access within the database environment could exploit this flaw to gain higher-level rights on the host.
Affected Systems
Affected products are Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), 2019 (Cumulative Update 32 and GDR), 2022 (Cumulative Update 26 and GDR), and 2025 (Cumulative Update 8 and GDR) on x64-based systems.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of <1% shows a very low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog. The flaw can be exploited by an attacker who already has authorized access to the SQL Server environment and can act over a network to obtain elevated privileges. Based on the description, it is inferred that the likely attack vector is a network-based exploitation from within the same database environment.
OpenCVE Enrichment