Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in Microsoft SQL Server. A user with sufficient privileges can construct malicious input that causes the server to execute arbitrary code when connecting over the network. This flaw allows an attacker to gain arbitrary code execution on the host system, compromising confidentiality, integrity, and availability. The weakness is categorized as CWE‑122.

Affected Systems

Affected installations include Microsoft SQL Server 2017 CU 31 and its corresponding GDR releases, Microsoft SQL Server 2019 CU 32 and its GDR releases, Microsoft SQL Server 2022 CU 26 and its GDR releases, as well as Microsoft SQL Server 2025 CU 8 and its x64 GDR releases. All 64‑bit editions of these products are vulnerable. The list of affected versions appears in the CNA data but no specific patch level is mentioned beyond the CU identifiers.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. EPSS is not available, so the current exploitation probability is unknown. The vulnerability is not in CISA’s KEV catalog. Attackers must be able to connect to the server and must possess permissions that allow the delivery of the exploit payload. If these conditions are met, the overflow can be triggered to gain unrestricted code execution.

Generated by OpenCVE AI on September 8, 2026 at 19:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑67388 through the Microsoft Security Response Center as listed in the update guide.
  • Ensure the SQL Server instance is not exposed to untrusted networks or restrict remote connections to trusted hosts only.
  • Enforce the principle of least privilege for database users and review account permissions to minimize the potential impact of an authorized attacker.

Generated by OpenCVE AI on September 8, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:34:39.952Z

Reserved: 2026-07-29T14:57:03.842Z

Link: CVE-2026-67388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:22.263

Modified: 2026-09-08T18:38:46.007

Link: CVE-2026-67388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:15:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow