Impact
A heap‑based buffer overflow in Microsoft SQL Server enables an attacker with authorized network access to execute arbitrary code. The vulnerability is triggered by a crafted packet sent over the network to an SQL Server instance, allowing the attacker to take control of the executing process.
Affected Systems
Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), and Microsoft SQL Server 2025 (CU 8 and GDR). All affected versions run on 64‑bit x64 systems.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. While the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. However, the attack requires network connectivity to a vulnerable SQL Server instance and authorized user credentials, meaning it is likely exploitable by a threat actor with legitimate access to the database network.
OpenCVE Enrichment