Impact
An out-of-bounds read bug in Microsoft SQL Server allows an attacker who has legitimate access to a database server to obtain private data that the server processes. The flaw permits reading memory outside the bounds of a buffer, which can expose sensitive data such as credentials or application state over the network. This vulnerability is an information‑disclosure flaw consistent with CWE‑125, affecting confidentiality but not integrity or availability directly.
Affected Systems
Affected are Microsoft SQL Server 2017, 2019, 2022, and 2025, specifically the cumulative update (CU) branches and the general distribution release (GDR) builds for each version on x64‑based machines.
Risk and Exploitability
The severity is scored 6.5 on the CVSS v3 scale, indicating a moderate risk. EPSS data is not provided, so the current exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits at the time of reporting. An attacker would need authenticated database access and the ability to send crafted requests to trigger the out‑of‑bounds read; the possibility of privilege escalation or lateral movement within an authenticated environment is inferred from the need for authentication and is not confirmed by the data.
OpenCVE Enrichment