Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in Microsoft SQL Server 2025 that can be triggered by an authorized attacker who can connect to the database instance from the network. The flaw allows the attacker to execute arbitrary code on the server with the privileges of the SQL Server service. This can lead to complete compromise of the affected machine, giving full control, potential data exfiltration, and persistence mechanisms.

Affected Systems

Microsoft SQL Server 2025 (Cumulative Update 8) and Microsoft SQL Server 2025 for x64‑based Systems (GDR) are affected. The flaw is present in the core server component used by these product lines and applies to the x64 architecture.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity. EPSS is not available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is network‑based, requiring an authenticated connection to the vulnerable SQL Server instance. Because the flaw can be triggered by any privileged user on the network, the potential impact is broad for environments where access is not strictly controlled.

Generated by OpenCVE AI on September 8, 2026 at 19:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update for Microsoft SQL Server 2025 (CU8) as published by Microsoft to remove the heap overflow bug.
  • Limit network exposure of the SQL Server instance by implementing firewall rules or virtual network isolation so that only trusted hosts can reach the database engine.
  • Enforce least‑privileged authentication and consider disabling legacy protocols that may expose the vulnerable component, then actively monitor for any anomalous activity on the server.

Generated by OpenCVE AI on September 8, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T19:17:10.399Z

Reserved: 2026-07-29T22:49:19.796Z

Link: CVE-2026-67642

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:11.357Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:24.410

Modified: 2026-09-08T20:17:40.030

Link: CVE-2026-67642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:15:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow