Impact
A heap‑based buffer overflow occurs within Microsoft SQL Server, allowing an attacker who possesses valid authentication to run arbitrary code on the database server. The flaw can be triggered remotely over a network connection, giving the attacker full control of the affected system. With a CVSS score of 8.8, the vulnerability is considered high severity and can compromise confidentiality, integrity, and availability of the database.
Affected Systems
The vulnerability affects several Microsoft SQL Server releases: SQL Server 2017 (CU 31 and GDR), SQL Server 2019 (CU 32 and GDR), SQL Server 2022 (CU 26 and GDR), and SQL Server 2025 (CU 8 plus the x64 GDR build). These products host the code path that mishandles heap memory, leading to the overflow.
Risk and Exploitability
The attack can be carried out by any authenticated user who can connect to the Microsoft SQL Server instance; no privileged or kernel‑level exploit is required. The CVSS score of 8.8 reflects a substantial impact, while the EPSS score is not available, making it difficult to gauge current exploitation activity. The vulnerability is not listed in CISA KEV, but its high severity and the potential for in‑network exploitation warrant immediate attention.
OpenCVE Enrichment