Impact
The vulnerability is a heap‑based buffer overflow in Microsoft SQL Server 2025. An authenticated attacker with network access can overflow a buffer and execute arbitrary code. The effect is that the attacker gains full control over the SQL Server instance and potentially the underlying host, which can lead to data theft, tampering, or disruption of services.
Affected Systems
Microsoft SQL Server 2025, including the Cumulative Update 8 rollout and the x64‑based GDR distribution, are affected. The issue is present in the x64 architecture configuration of SQL Server 2025.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity scenario. EPSS data is unavailable, but the overflow requires only authenticated network access, narrowing the exploitable surface to users who can connect to the database. The vulnerability is not listed in CISA KEV, yet remote code execution remains a critical risk that could be leveraged by adversaries within the trusted / internal network.
OpenCVE Enrichment