Description
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow or wraparound flaw in Microsoft SQL Server allows an attacker who already has authorized access to cause a denial of service by sending specially crafted SQL requests over the network. The overflow corrupts internal buffers, resulting in a crash or unresponsiveness of the database engine and interrupting availability for the targeted organization.

Affected Systems

Microsoft SQL Server 2022 CU 26, Microsoft SQL Server 2022 GDR, Microsoft SQL Server 2025 CU8, and Microsoft SQL Server 2025 x64-based Systems GDR are the affected products.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate to high risk, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote over the network, as the description states that the denial of service can be triggered over a network. The need for authorized access suggests that the threat is significant for environments where privileged users are compromised or where the database is exposed to untrusted networks.

Generated by OpenCVE AI on September 8, 2026 at 19:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update that contains the integer overflow fix for the affected SQL Server versions.
  • If a patch cannot be applied immediately, isolate the database server from untrusted networks using firewall rules or network segmentation to limit access to the vulnerable endpoint.
  • Monitor database and system logs for abnormal crash events or memory corruption patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 8, 2026 at 19:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
Title Microsoft SQL Server Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-190
CPEs cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T20:50:52.092Z

Reserved: 2026-07-29T22:49:19.796Z

Link: CVE-2026-67641

cve-icon Vulnrichment

Updated: 2026-09-08T20:50:45.309Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:24.280

Modified: 2026-09-08T21:18:26.250

Link: CVE-2026-67641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:15:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound