Impact
The vulnerability is a stack-based buffer overflow in Microsoft SQL Server that permits an authenticated attacker with network access to execute arbitrary code. The flaw stems from improper bounds checking when processing certain network requests, a weakness classified as CWE‑121. If exploited, the attacker could gain the privileges of the SQL Server service on the host, potentially compromising confidentiality, integrity, and availability of databases and the underlying operating system.
Affected Systems
Affected products include Microsoft SQL Server 2019 through its cumulative update 32 and guarantee data recovery (GDR), SQL Server 2022 cumulative update 26 and GDR, and SQL Server 2025 cumulative update 8 and GDR for x64‑based systems. The vulnerability spans all x64 editions of these versions.
Risk and Exploitability
The CVSS score of 8.5 indicates a high-impact threat. EPSS is not available, so the exploit probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The attack vector is over a network, requiring authenticated access, yet the buffer overflow can provide local code execution on the SQL Server service. Organizations running the affected versions should assume the vulnerability is exploitable unless mitigated by applying the vendor update or restricting network exposure.
OpenCVE Enrichment