Impact
The vulnerability is an out-of-bounds read in Microsoft SQL Server that enables an authorized attacker to disclose sensitive information over a network. The flaw is a classic buffer overread, classified as CWE-125, and leads primarily to confidentiality compromise without impacting integrity or availability.
Affected Systems
Affected products include Microsoft SQL Server 2017 (CU 31 and GDR), SQL Server 2019 (CU 32 and GDR), SQL Server 2022 (CU 26 and GDR), and SQL Server 2025 (CU 8 and GDR). These versions are deployed on x64‑based systems.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires an attacker who is already authorized to access the SQL Server instance, making the exploitation scenario more limited in scope but still significant for internal or privileged users.
OpenCVE Enrichment