Impact
An integer overflow or wraparound flaw in Microsoft SQL Server allows an attacker who already has authorized access to cause a denial of service by sending specially crafted SQL requests over the network. The overflow corrupts internal buffers, resulting in a crash or unresponsiveness of the database engine and interrupting availability for the targeted organization.
Affected Systems
Microsoft SQL Server 2022 CU 26, Microsoft SQL Server 2022 GDR, Microsoft SQL Server 2025 CU8, and Microsoft SQL Server 2025 x64-based Systems GDR are the affected products.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote over the network, as the description states that the denial of service can be triggered over a network. The need for authorized access suggests that the threat is significant for environments where privileged users are compromised or where the database is exposed to untrusted networks.
OpenCVE Enrichment