Impact
The vulnerability is an out-of-bounds read in Microsoft SQL Server that allows an authorized attacker to read memory beyond the intended bounds, resulting in the disclosure of internal data over the network. This is classified as a confidentiality breach and is identified as CWE-125.
Affected Systems
Affected versions include Microsoft SQL Server 2022 CU 26 and the GDR release, as well as Microsoft SQL Server 2025 CU 8 and its GDR release, all 64-bit editions. These editions are distributed across Windows Server platforms and are targeted by the described vulnerability.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity level. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalogue, suggesting no publicly observed exploitation. The attack vector is inferred to be network based, requiring an authorized user who can access the SQL Server instance. With such privileges, the attacker can trigger the out-of-bounds read to exfiltrate confidential data.
OpenCVE Enrichment