Impact
The vulnerability is a buffer over-read in SQL Server that allows an authorized attacker to read beyond a buffer boundary, potentially exposing sensitive data over the network. This weakness is classified as CWE-126, a classic buffer over-read scenario.
Affected Systems
Affected products include Microsoft SQL Server 2017 CU31 and the GDR release, Microsoft SQL Server 2019 CU32 and the GDR release, Microsoft SQL Server 2022 CU26 and the GDR release, and Microsoft SQL Server 2025 CU8 along with the 2025 GDR release for x64-based systems. All variants are affected when running on 64‑bit platforms.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation risk may be limited to organizations that have publicly exposed SQL Server instances. The likely attack vector is a network-based attack conducted by an attacker who already has authorized access to the SQL Server service. With such access, the attacker can trigger the over-read to obtain confidential information that resides adjacent to the target buffer in memory.
OpenCVE Enrichment