Impact
Use of an uninitialized resource within Microsoft SQL Server enables an authorized attacker to read confidential data over the network. The flaw does not permit code execution but exposes sensitive information that the attacker is already able to access through legitimate authentication channels.
Affected Systems
Affected products include Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), Microsoft SQL Server 2019 (Cumulative Update 32 and GDR), Microsoft SQL Server 2022 (Cumulative Update 26 and GDR), and Microsoft SQL Server 2025 (Cumulative Update 8 and GDR for x64-based systems).
Risk and Exploitability
The vulnerability receives a CVSS score of 6.5, indicating moderate severity, and no EPSS information is available. It is not present in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector requires an authenticated session to the SQL Server instance, so the threat is confined to attackers who already possess valid credentials or have gained local or network-level access. However, any system that is exposed to the network and contains the affected SQL Server releases remains at risk for unauthorized data viewing.
OpenCVE Enrichment