Impact
This vulnerability is a heap‑based buffer overflow in Microsoft SQL Server that grants an authorized attacker the ability to execute code over the network. The overflow allows the attacker to inject and run arbitrary instructions within the SQL Server process, leading to full compromise of the database instance. The weakness is classified as CWE‑122.
Affected Systems
Affected products include Microsoft SQL Server 2022 cumulatively updated to CU 26 or its GDR release, Microsoft SQL Server 2025 CU 8, and Microsoft SQL Server 2025 for x64‑based systems in GDR. These specific versions are listed as impacted by the Microsoft security advisory.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity. The EPSS score is not available, but the lack of a KEV listing suggests no publicly known exploitation yet. Based on the description, the likely attack vector is a network‑based attack carried out by an authenticated user with sufficient privileges, which can then take over the database process. The overall risk is high for environments that expose SQL Server to untrusted networks without adequate segmentation or access controls.
OpenCVE Enrichment