Impact
Integer overflow or wraparound in Microsoft SQL Server can be triggered by special input values that exceed integer limits. When processed, the flaw causes the server to crash, denying service to legitimate users. The vulnerability is an integer overflow weakness (CWE-190) and can lead to a loss of availability, disrupting business operations. The description indicates an unauthorized attacker can trigger the DoS remotely, although specific internal mechanisms are not detailed in the input.
Affected Systems
Microsoft SQL Server 2017 when updated to Cumulative Update 31 or its General Distribution Release, Microsoft SQL Server 2019 with Cumulative Update 32 or its GDR, Microsoft SQL Server 2022 with Cumulative Update 26 or its GDR, and Microsoft SQL Server 2025 updated to Cumulative Update 8 or its GDR for x64 systems are the editions and versions identified as impacted by the integer overflow flaw.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating medium‑high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit it from an unauthorized remote connection by sending crafted traffic that triggers the integer overflow, causing the SQL Server process to terminate and denying service. Because no authentication is required, any exposed instance is at risk unless the relevant cumulative update is applied.
OpenCVE Enrichment