Description
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read bug in Microsoft SQL Server allows an attacker who has legitimate access to a database server to obtain private data that the server processes. The flaw permits reading memory outside the bounds of a buffer, which can expose sensitive data such as credentials or application state over the network. This vulnerability is an information‑disclosure flaw consistent with CWE‑125, affecting confidentiality but not integrity or availability directly.

Affected Systems

Affected are Microsoft SQL Server 2017, 2019, 2022, and 2025, specifically the cumulative update (CU) branches and the general distribution release (GDR) builds for each version on x64‑based machines.

Risk and Exploitability

The severity is scored 6.5 on the CVSS v3 scale, indicating a moderate risk. EPSS data is not provided, so the current exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits at the time of reporting. An attacker would need authenticated database access and the ability to send crafted requests to trigger the out‑of‑bounds read; the possibility of privilege escalation or lateral movement within an authenticated environment is inferred from the need for authentication and is not confirmed by the data.

Generated by OpenCVE AI on September 8, 2026 at 19:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest available cumulative update or service pack for the affected SQL Server version.
  • Restrict database user privileges so only trusted administrators can connect from networked hosts.
  • Segment the network to limit exposure of the SQL Server instance and apply firewall rules that allow inbound traffic only from known hosts.

Generated by OpenCVE AI on September 8, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Title Microsoft SQL Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:38:46.688Z

Reserved: 2026-07-29T22:49:19.797Z

Link: CVE-2026-67645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:24.660

Modified: 2026-09-08T18:39:13.460

Link: CVE-2026-67645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:30:07Z

Weaknesses