Impact
An integer overflow or wraparound in Microsoft SQL Server can be triggered by an authorized attacker with network access, allowing the attacker to execute arbitrary code on the server. The flaw grants direct code execution when an attacker manipulates specific integer values during query processing, compromising the confidentiality, integrity, and availability of the affected database systems.
Affected Systems
Affected versions include Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), and Microsoft SQL Server 2025 (CU 8 and GDR) running on x64-based systems.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires attacker authentication and network access to the SQL Server instance; once the integer overflow is leveraged the attacker gains full code execution privileges on the host. The lack of publicized exploits suggests a moderate to high likelihood of future exploitation.
OpenCVE Enrichment