Impact
The vulnerability is a heap‑based buffer overflow in Microsoft SQL Server that allows an authorized attacker to execute arbitrary code locally. The flaw arises when malformed data is processed by the query engine, leading to corrupted heap memory. Because the buffer overrun can cause arbitrary code execution, the compromise grants the attacker the privileges of the SQL Server service account.
Affected Systems
Affected are Microsoft SQL Server 2017, 2019, 2022, and 2025 on x64 systems. Specific vulnerable releases include the cumulative update (CU) 31 for 2017, CU 32 for 2019, CU 26 for 2022, and CU 8 for 2025, as well as the corresponding any exposure fixes (GDR) for each version. These apply to 64‑bit editions of the database engine.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. EPSS is not available, and the issue is not yet listed in CISA’s KEV catalog. Because the vulnerability requires an authorized attacker, the likely attack vector is a privileged user or a compromised account that can submit specially crafted requests to the SQL Server service. Once exploited, the attacker gains code execution with the SQL Server service account privileges. The absence of publicly known exploits and lack of KEV listing suggest that exploitation is not widely automated yet, but the high severity warrants immediate patching.
OpenCVE Enrichment