Impact
Improper neutralization of special elements in a SQL command can lead to an SQL injection scenario that allows an attacker with legitimate access to the database to execute malicious queries and elevate their privileges. The vulnerability is rooted in CWE‑89, where insufficient input validation permits the injection of arbitrary SQL statements. An attacker who can send crafted requests over the network can potentially gain higher level permissions within the SQL Server instance, enabling them to read, modify or delete data, alter database schemas, or gain administrative access to the underlying operating system if backdoor access is available.
Affected Systems
Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), and Microsoft SQL Server 2025 (CU 8 and GDR) on x64‑based systems are all impacted by this flaw.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. An attacker who is already authenticated to the database or application can exploit this over a network connection, bypassing established role boundaries. EPSS data is currently unavailable, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no confirmed active exploits as of the latest data. Nonetheless, the potential for privilege escalation makes this a critical risk for organizations that rely on these SQL Server versions.
OpenCVE Enrichment