Impact
This vulnerability stems from the use of an uninitialized resource within SQL Server (CWE-908). An attacker who has authorized access can exploit the flaw to read sensitive data over a network connection. The weakness allows the disclosure of information that should be protected, potentially compromising confidentiality of databases and application data.
Affected Systems
Affected products are Microsoft SQL Server editions 2017, 2019, 2022, and 2025, limited to the cumulative update or GDR builds listed: SQL Server 2017 CU 31 and GDR; SQL Server 2019 CU 32 and GDR; SQL Server 2022 CU 26 and GDR; SQL Server 2025 CU 8 and GDR for x64-based systems.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and have network access to the SQL Server instance. Once the flaw is leveraged, data visibility is elevated, potentially giving the attacker insight into confidential database contents.
OpenCVE Enrichment