Impact
An out‑of‑bounds read vulnerability exists in Microsoft SQL Server. The flaw allows an attacker with authorized access to send specially crafted requests that result in reading data beyond intended bounds, exposing sensitive information to the attacker over the network. Because the data is exposed, an attacker can harvest confidential strings, passwords, or other sensitive configuration data, compromising confidentiality and potentially providing a foothold for further attacks. The weakness is a classic buffer over‑read (CWE‑125).
Affected Systems
Microsoft SQL Server 2017 CU 31 and later GDR releases, 2019 CU 32 and later GDR releases, 2022 CU 26 and later GDR releases, and 2025 CU 8 and associated GDR releases on x64 systems are affected. These versions are actively supported for enterprise customers and the vulnerability was disclosed for both CU and GDR updates. Administrators should verify that the affected SQL Server instances are running a patched version.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, while the EPSS score is not available, indicating no publicly available data about exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Because the issue is triggered by an authorized user sending a crafted request over the network, the attack vector is network (LAN or internet) and requires an active connection to the vulnerable SQL Server. Once exploited, the attacker can read arbitrary memory content from the server, leading to disclosure of sensitive data. Mitigation relies on applying the vendor‑provided update; lacking that, limiting network exposure and enforcing strict privilege boundaries can reduce risk.
OpenCVE Enrichment