Impact
The vulnerability is a heap-based buffer overflow in Microsoft SQL Server. A user with sufficient privileges can construct malicious input that causes the server to execute arbitrary code when connecting over the network. This flaw allows an attacker to gain arbitrary code execution on the host system, compromising confidentiality, integrity, and availability. The weakness is categorized as CWE‑122.
Affected Systems
Affected installations include Microsoft SQL Server 2017 CU 31 and its corresponding GDR releases, Microsoft SQL Server 2019 CU 32 and its GDR releases, Microsoft SQL Server 2022 CU 26 and its GDR releases, as well as Microsoft SQL Server 2025 CU 8 and its x64 GDR releases. All 64‑bit editions of these products are vulnerable. The list of affected versions appears in the CNA data but no specific patch level is mentioned beyond the CU identifiers.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS is not available, so the current exploitation probability is unknown. The vulnerability is not in CISA’s KEV catalog. Attackers must be able to connect to the server and must possess permissions that allow the delivery of the exploit payload. If these conditions are met, the overflow can be triggered to gain unrestricted code execution.
OpenCVE Enrichment