Impact
The vulnerability is an out‑of‑bounds read in Microsoft SQL Server, permitting an attacker with valid authorization to cause a denial of service over the network. The flaw is a classic CWE‑125 condition, allowing the server to read memory beyond its allocated bounds, which typically triggers a crash or hangs. Because the issue arises only from a crafted request sent by an authorized user, it does not directly enable remote code execution, but can disrupt critical database services.
Affected Systems
Affected products include Microsoft SQL Server 2017 (CU 31) and the global defect review version, SQL Server 2019 (CU 32 and GDR), SQL Server 2022 (CU 26 and GDR), and SQL Server 2025 (CU 8 and the x64 GDR). All affected builds run on 64‑bit architectures, and only the specified cumulative updates or GDR releases are impacted. No other versions were reported to contain this flaw.
Risk and Exploitability
The CVSS score is 6.5, which indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based, requiring the attacker to be authenticated to the target database or otherwise possess the legal authority to send queries. Exploitation will terminate or hang the SQL Server service, leading to service downtime for users. Because no exploitation probability is known and the flaw requires a privileged user, the risk remains moderate, but the potential impact on availability is significant for mission‑critical workloads.
OpenCVE Enrichment