Impact
Based on the description, it is inferred that an authorized attacker with authenticated access to the SQL Server instance can read internal memory and transmit the leaked data over the network. The flaw is a classic bounds‑checking failure, classified as CWE‑125, and could expose sensitive database contents or configuration information to such an attacker.
Affected Systems
Microsoft SQL Server 2017 on the 64‑bit platform when the cumulative update is at CU 31 or the GDR, Microsoft SQL Server 2019 at CU 32 or the GDR, Microsoft SQL Server 2022 at CU 26 or the GDR, and Microsoft SQL Server 2025 at CU 8 or the GDR for x64‑based installations.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in CISA’s KEV catalog. An attacker must already possess valid credentials to the database engine, so the attack surface is limited to authenticated users or compromised accounts. Because the flaw permits remote disclosure of memory contents rather than code execution, the threat primarily centers on data exposure rather than service disruption. Patching or upgrading mitigates the risk.
OpenCVE Enrichment