Impact
A heap‑based buffer overflow exists in Microsoft SQL Server that permits an attacker who can authenticate with the database engine to execute arbitrary code within the SQL Server process. The flaw falls under CWE‑122 and, when successfully exploited, grants the attacker full control over the database engine, enabling the execution of any code with the same privileges the server process runs under.
Affected Systems
Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), 2019 (Cumulative Update 32 and GDR), 2022 (Cumulative Update 26 and GDR), and 2025 (Cumulative Update 8 and GDR) on 64‑bit platforms are affected.
Risk and Exploitability
The CVSS score of 8.8 conveys a high severity rating. EPSS data are not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑connected, authorized attacker who can form specially crafted requests against the vulnerable SQL Server instance; exploitation requires constructing payloads that overflow a heap allocation and gain code‑execution privileges.
OpenCVE Enrichment