Impact
The vulnerability is a heap-based buffer overflow in Microsoft SQL Server that allows an authorized attacker to execute arbitrary code over the network. Because the flaw resides in a core component of the database engine, successful exploitation results in full control of the affected server. The critical weakness is identified as CWE-122, indicating a classic buffer overflow scenario.
Affected Systems
Affected are Microsoft SQL Server 2017 CU 31 and its GDR, SQL Server 2019 CU 32 and its GDR, SQL Server 2022 CU 26 and its GDR, and SQL Server 2025 CU 8 plus the GDR for x64-based systems. These versions are listed by Microsoft as vulnerable and also appear in the provided product list. No other versions or editions are mentioned.
Risk and Exploitability
The CVSS score of 4.9 places this vulnerability in the moderate category, but the potential impact of remote code execution warrants immediate attention. The EPSS score of less than 1% indicates that the probability of exploitation in the wild is currently low, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector requires the attacker to be authorized on the network, which is a realistic condition for many hosts. Because the flaw is a buffer overflow, exploitation requires sending a crafted packet to the database engine; no privilege escalation is needed beyond the existing authorized access.
OpenCVE Enrichment