Impact
The vulnerability is an out-of-bounds read in Microsoft SQL Server that enables an unauthenticated attacker to read memory contents. This flaw, classified as CWE‑125, can expose sensitive data stored within the database or on the host. The CVE description indicates the attacker can disclose information over a network.
Affected Systems
Microsoft SQL Server 2017 (CU 31 and GDR) and Microsoft SQL Server 2019 (CU 32 and GDR) on 64‑bit installations are affected. The issue is present in the server binaries served through the default network ports.
Risk and Exploitability
The CVSS score of 6.5 marks the vulnerability as medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, implying limited evidence of widespread exploitation. The attack vector is remote over the network; authentication is not required to trigger the read, allowing any host that can reach the server to potentially dissect memory. Organizations with exposed SQL Server instances face a higher risk.
OpenCVE Enrichment