Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 4.9 Medium
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in Microsoft SQL Server that allows an authorized attacker to execute arbitrary code over the network. Because the flaw resides in a core component of the database engine, successful exploitation results in full control of the affected server. The critical weakness is identified as CWE-122, indicating a classic buffer overflow scenario.

Affected Systems

Affected are Microsoft SQL Server 2017 CU 31 and its GDR, SQL Server 2019 CU 32 and its GDR, SQL Server 2022 CU 26 and its GDR, and SQL Server 2025 CU 8 plus the GDR for x64-based systems. These versions are listed by Microsoft as vulnerable and also appear in the provided product list. No other versions or editions are mentioned.

Risk and Exploitability

The CVSS score of 4.9 places this vulnerability in the moderate category, but the potential impact of remote code execution warrants immediate attention. The EPSS score of less than 1% indicates that the probability of exploitation in the wild is currently low, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector requires the attacker to be authorized on the network, which is a realistic condition for many hosts. Because the flaw is a buffer overflow, exploitation requires sending a crafted packet to the database engine; no privilege escalation is needed beyond the existing authorized access.

Generated by OpenCVE AI on September 10, 2026 at 04:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Microsoft's latest cumulative update or GDR for the installed SQL Server version to patch the heap overflow.
  • Restart the SQL Server service to load the updated binaries.
  • Restrict network connectivity to the SQL Server by applying firewall rules or IP whitelisting to limit access to trusted hosts.

Generated by OpenCVE AI on September 10, 2026 at 04:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Fri, 11 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:39.913Z

Reserved: 2026-07-31T16:33:08.215Z

Link: CVE-2026-68785

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:41.747Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:26.053

Modified: 2026-09-15T19:58:28.560

Link: CVE-2026-68785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:45:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow