Impact
This vulnerability is a CWE-122 heap-based buffer overflow that allows a malicious actor with authorized access to send crafted packets over a network and execute arbitrary code on the target system. The consequence of executing code would be a full compromise of the instance and potentially the host operating system, leading to loss of confidentiality, integrity, and availability. The CVSS score of 8.8 indicates a high severity level for this type of flaw.
Affected Systems
Affected releases are Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), Microsoft SQL Server 2019 (Cumulative Update 32 and GDR), Microsoft SQL Server 2022 (Cumulative Update 26 and GDR), and Microsoft SQL Server 2025 (Cumulative Update 8 and GDR) on x64-based systems.
Risk and Exploitability
The vulnerability is listed with a CVSS of 8.8, but the EPSS score is not available and it is not currently in the CISA KEV catalog. Because the flaw requires an authorized attacker who can communicate over the network, the likelihood of exploitation depends on the attack surface and user privileges. Nevertheless, the high severity score and remote code execution capability warrant a significant risk assessment and prioritization for remediation.
OpenCVE Enrichment