Impact
The vulnerability is a use‑after‑free flaw in Microsoft SQL Server that permits an attacker with authorized access to execute arbitrary code over a network connection. The attack can lead to remote code execution on the affected database server.
Affected Systems
Microsoft SQL Server 2017 (CU 31 and GDR), 2019 (CU 32 and GDR), 2022 (CU 26 and GDR), and 2025 (CU 8 and GDR) running on x64 architectures are affected, as identified by Microsoft through cumulative updates and generalized defect releases.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker with authorized access and network connectivity to the SQL Server instance, as the use‑after‑free condition allows arbitrary code execution upon receipt of crafted input. The risk is therefore high when such access exists.
OpenCVE Enrichment