Impact
This vulnerability is an out‑of‑bounds read in Microsoft SQL Server that permits an attacker with authorization to the server to read memory contents that the database should not expose, resulting in the disclosure of sensitive information over the network. The weakness is a classic buffer‑overread (CWE‑125) and allows data leakage of arbitrary bytes in the process memory. If an adversary can manipulate queries or exploit the read, they may gain confidential data or keys stored in memory.
Affected Systems
Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), Microsoft SQL Server 2025 (CU 8) and Microsoft SQL Server 2025 for x64‑based Systems GDR. All of these releases target the x64 platform and are listed in the CNA data as affected products.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk. The EPSS score is not available, so the exploit probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, implying no documented exploits as of this analysis. Because the vulnerability requires an attacker to have valid credentials or an authorized connection to the SQL Server instance, the attack vector is inferred to be a network‑based, authenticated attack. An attacker who can issue SQL commands may use the out‑of‑bounds read to retrieve restricted memory contents, compromising data confidentiality across the affected systems.
OpenCVE Enrichment