Impact
A heap-based buffer overflow flaw in Microsoft SQL Server allows an attacker who already has authorized access to the database system to execute arbitrary code over the network. The weakness is a classic out‑of‑bounds write, classified as CWE‑122, and if successfully exploited the attacker can take control of the database engine process, potentially leading to full compromise of the underlying host.
Affected Systems
Affected products are Microsoft SQL Server 2017 in CU 31 and GDR releases, Microsoft SQL Server 2019 in CU 32 and GDR releases, Microsoft SQL Server 2022 in CU 26 and GDR releases, and Microsoft SQL Server 2025 in CU 8 and the GDR build for x64‑based systems. All affected instances are the x64 editions of these products.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. Because the vulnerability is exploitable only by an attacker with existing authorized network access, the attack vector is typically an authenticated session or a trustworthy user account that can query the server. The EPSS score is not available, so current exploitation frequency is unknown, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, a successful exploitation would give the attacker remote code execution on the database server, leaving the system and any connected applications exposed.
OpenCVE Enrichment