Impact
The vulnerability is an out‑of‑bounds read in Microsoft SQL Server that permits an authorized attacker to read memory contents and disclose sensitive data over the network. This flaw arises from improper bounds checking during data handling, classified as CWE-125. An attacker who can authenticate to the SQL Server instance can therefore obtain confidential information that was not intended to be exposed, leading to a confidentiality breach.
Affected Systems
Affected systems include Microsoft SQL Server 2017 released as 31st cumulative update or the GDR release; Microsoft SQL Server 2019 released as 32nd cumulative update or the GDR release; Microsoft SQL Server 2022 released as 26th cumulative update or the GDR release; and Microsoft SQL Server 2025 released as 8th cumulative update or the GDR release for x64-based systems. These updates are available for the x64 architecture as listed in the CNA affected-product data.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. EPSS is not available, so the probability of exploitation cannot be quantified at this time, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires that the attacker already have authorized access to the database engine; therefore the attack vector is likely by an authenticated network user. An adversary could read arbitrary memory contents that may contain passwords, cryptographic keys, or other sensitive data, which could facilitate further compromise or insider threats. No public exploits are known.
OpenCVE Enrichment