Impact
An insufficient granularity of access control in Microsoft SQL Server permits an authorized attacker to increase their privileges across the network, effectively allowing them to perform actions beyond their assigned permissions. The vulnerability, classified as CWE-1220, is an access control flaw that can lead to unauthorized system access and manipulation of database resources.
Affected Systems
Affected versions include Microsoft SQL Server 2017 (Cumulative Update 31 and GDR), SQL Server 2019 (CU 32 and GDR), SQL Server 2022 (CU 26 and GDR), and SQL Server 2025 (CU 8 and GDR). These releases are for x64-based systems and are listed in the Microsoft SQL Server product line.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over a network where the attacker already has authorized access. Exploitation requires the attacker to use their existing account to elevate privileges, amplifying risk to confidentiality, integrity, and availability of database services.
OpenCVE Enrichment