Impact
The vulnerability is an untrusted pointer dereference in Microsoft SQL Server that allows an attacker who has authorized access to execute arbitrary code on the server. Because the flaw is triggered by network traffic, the attacker does not need elevated OS privileges to exploit it; the impact is full compromise of the SQL Server instance, including confidentiality, integrity, and availability of the data it manages.
Affected Systems
Affected are Microsoft SQL Server 2019 (CU 32 and GDR), SQL Server 2022 (CU 26 and GDR), and SQL Server 2025 (CU8 and GDR) for x64-based systems.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. EPSS data is not available, but the fact that the flaw requires an authorized attacker and is network-exposed implies a realistic attack scenario. It is not listed in the CISA KEV catalog, suggesting no known widespread exploitation, yet the potential for malicious use remains high.
OpenCVE Enrichment