Impact
A buffer over‑read exists in Microsoft SQL Server that can be triggered by an attacker who already has authorized database access. The fault allows the attacker to read memory beyond a buffer boundary and expose data that should not be accessible over the network, thereby compromising the confidentiality of sensitive information stored in the database. The weakness is classified as CWE‑126, a classic buffer over-read vulnerability.
Affected Systems
The flaw affects Microsoft SQL Server 2017 through 2025, including the CU 31 and GDR releases of 2017, CU 32 and GDR of 2019, CU 26 and GDR of 2022, and CU 8 and the x64 GDR release of 2025. All affected editions are the 64‑bit builds as listed in the CPE identifiers.
Risk and Exploitability
The CVSS base score is 6.5, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers must already possess authorized credentials to communicate with the SQL Server instance; therefore the exploit requires network access to the database server and valid authentication. Given the requirement for authorized access, the likelihood of exploitation is less than for a fully remote vulnerability, but the potential for credential compromise or lateral movement remains significant.
OpenCVE Enrichment