Impact
An error message generated inside Microsoft SQL Server can contain sensitive data, allowing an attacker with authorized privileges to read confidential information exposed over the network. The flaw stems from improper sanitization of error content, leading to disclosure of internal state or configuration details.
Affected Systems
Microsoft SQL Server 2025 (CU8) and Microsoft SQL Server 2025 for x64‐based Systems (GDR) are directly affected. Users running these specific builds on x64 environments should verify their update status.
Risk and Exploitability
The vulnerability is rated CVSS 6.5, indicating moderate severity. EPSS information is unavailable, and the issue is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The attack requires an attacker already possessing authorized access to the SQL Server instance and the ability to trigger the error condition, which may be achieved by sending crafted queries. Although the flaw does not grant code execution, it permits disclosure of sensitive data through error messages, thereby compromising confidentiality.
OpenCVE Enrichment