Impact
Buffer over-read in Microsoft SQL Server enables an authorized attacker to read memory beyond the intended buffer boundaries over a network interface, resulting in the disclosure of sensitive data. This information disclosure flaw can reveal confidential data or internal state of the database environment. The weakness is classified as a buffer over-read (CWE-126).
Affected Systems
Products impacted include Microsoft SQL Server 2019 CU 32 and GDR, SQL Server 2022 CU 26 and GDR, and SQL Server 2025 CU8 and GDR, all on x64-based systems. The issue applies to all instances of these versions that have not applied the latest cumulative update referenced by Microsoft.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered medium severity. The EPSS score is not available, and it has not been listed in the CISA KEV catalog. The exploit requires an attacker to have authorized credentials against the SQL Server instance. Because the attacker must already be authenticated, the risk is limited to the scope of the database host or network segment where the instance resides. The impact is confined to the protected data, and there is no evidence of additional privilege escalation or lateral movement beyond the database context.
OpenCVE Enrichment