Impact
An improper access control weakness in Microsoft SQL Server allows an attacker who already has legitimate access to the database to increase their privileges when communicating over a network. This flaw can enable a user with limited rights to obtain higher permissions, potentially giving them full control over the database instance and the underlying operating system if the SQL Server process has elevated rights. The CVSS score of 8.8 indicates a high severity, and although no EPSS value is available, the lack of a KEV listing suggests that the vulnerability has not yet been widely exploited in the wild, but the risk remains significant for any unpatched system
Affected Systems
Microsoft SQL Server 2017 cumulative update 31 and the GDR, Microsoft SQL Server 2019 cumulative update 32 and the GDR, Microsoft SQL Server 2022 cumulative update 26 and the GDR, and Microsoft SQL Server 2025 cumulative update 8 and the GDR, all for x64‑based systems
Risk and Exploitability
The weakness is identified as CWE‑284, an access control failure. The flaw can be exploited by a legitimate user who bypasses the intended permission checks to elevate rights over the network. The attack vector is inferred to be remote, as the description states “over a network.” The absence of an EPSS score provides no quantitative indication of exploitation probability, but the high CVSS score and the potential for complete compromise mean that the vulnerability should be treated with urgency. No KEV listing means the vulnerability has not been publicly confirmed to be exploited, yet the impact of compromise is severe if the flaw is leveraged.
OpenCVE Enrichment