Impact
Out‑of‑bounds reads in Microsoft SQL Server allow an attacker with authorized access to read memory beyond the intended buffer and transmit that data over the network, potentially exposing sensitive database contents and other internal information. This flaw is classified as CWE‑125 and results in unauthorized disclosure of confidential information. The impact is not limited to a single user but can affect all data accessible through the compromised instance.
Affected Systems
Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), and Microsoft SQL Server 2025 (CU 8 and GDR for x64‑based systems) are affected. Only the x64 builds of these releases contain the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The flaw is exploitable by users who already possess some level of authorization within the SQL Server environment, implying that an attacker with legitimate credentials or elevated privileges can trigger the out‑of‑bounds read. The likely attack vector is network‑based, as the disclosure occurs during normal client-server communication; however, this inference is based on the description of network disclosure and is not explicitly stated in the advisory.
OpenCVE Enrichment