Impact
A heap‑based buffer overflow exists in Microsoft SQL Server 2025 that is triggered when the server receives a specially crafted network packet. The flaw allows an attacker with authorized or authenticated access to execute arbitrary code on the database server, leading to full compromise of the impacted system and potential lateral movement.
Affected Systems
The vulnerability affects Microsoft SQL Server 2025 CU8 and the 2025 for x64‑based Systems GDR release. Any instance of SQL Server 2025 running either of these configurations and exposed over the network is impacted.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. Exploitation requires an attacker with authorized access or a valid authentication session, but a single malicious packet can trigger the heap buffer overflow and spawn arbitrary code. No EPSS score is available, and the vulnerability is not in the CISA KEV catalog. The risk is therefore primarily for environments where SQL Server is reachable over a network and users have or could obtain authorized credentials. Without a public exploit, the threat remains an opportunity that could be leveraged by adversaries with network access and suitable privileges.
OpenCVE Enrichment