Impact
An out‑of‑bounds read flaw in Microsoft SQL Server allows an authorized attacker to read data beyond intended boundaries, leading to disclosure of sensitive information over the network. The weakness is classified as CWE‑125, and the primary impact is compromised confidentiality as the attacker can gather information that should be protected by the database.
Affected Systems
Microsoft SQL Server 2017 (CU 31, GDR), Microsoft SQL Server 2019 (CU 32, GDR), Microsoft SQL Server 2022 (CU 26, GDR), and Microsoft SQL Server 2025 (CU 8, GDR) running on x64-based systems are affected. These versions have a known out‑of‑bounds read vulnerability that can be triggered by an authenticated user.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The attacker must already have authorized access to the instance; exploitation can be carried out through normal database operations over the network, allowing the adversary to read data that should be hidden. No privilege escalation or code execution is gained, but the confidentiality of stored data is at risk.
OpenCVE Enrichment