Impact
An out‑of‑bounds read in Microsoft SQL Server allows an authorized attacker to read sensitive data from memory and transmit it over a network connection. The weakness enables disclosure of confidential information, earning a CWE‑125 designation for out‑of‑bounds read faults.
Affected Systems
Affected are Microsoft SQL Server 2017, version CU 31 and the GDR release, Microsoft SQL Server 2019, version CU 32 and the GDR release, Microsoft SQL Server 2022, version CU 26 and the GDR release, and Microsoft SQL Server 2025, version CU 8 and the GDR release – all on x64 platforms.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the data. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authorized user with privileges to send network requests to the SQL Server instance; the attacker could then capture and transmit sensitive information to a remote host.
OpenCVE Enrichment