Impact
The vulnerability is a heap‑based buffer overflow located in SQL Server code that permits an attacker who already has some form of authorized access to gain higher privileges on the database server. Successful exploitation can lead to unauthorized control over database objects or escalation to administrative rights, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Affected versions include Microsoft SQL Server 2017 CU31, SQL Server 2017 GDR, SQL Server 2019 CU32, SQL Server 2019 GDR, SQL Server 2022 CU26, SQL Server 2022 GDR, SQL Server 2025 CU8, and SQL Server 2025 for x64‑based Systems GDR. The issue applies to all 64‑bit editions of these releases.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread public exploit has been documented yet. The likely attack vector is a network‑based exploit performed by an authorized user or compromised account, taking advantage of direct access to the SQL Server instance or a privileged role that can trigger the vulnerable routine. No public exploit code is currently known to be publicly available.
OpenCVE Enrichment