Impact
A heap‑based buffer overflow exists in Microsoft SQL Server 2025 that can be triggered by an authorized attacker who can connect to the database instance from the network. The flaw allows the attacker to execute arbitrary code on the server with the privileges of the SQL Server service. This can lead to complete compromise of the affected machine, giving full control, potential data exfiltration, and persistence mechanisms.
Affected Systems
Microsoft SQL Server 2025 (Cumulative Update 8) and Microsoft SQL Server 2025 for x64‑based Systems (GDR) are affected. The flaw is present in the core server component used by these product lines and applies to the x64 architecture.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. EPSS is not available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is network‑based, requiring an authenticated connection to the vulnerable SQL Server instance. Because the flaw can be triggered by any privileged user on the network, the potential impact is broad for environments where access is not strictly controlled.
OpenCVE Enrichment