Description
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a heap‑based buffer overflow that can be triggered by an unauthorized attacker using a crafted payload delivered over the network. When successfully exploited, the attacker can execute arbitrary code with the privileges of the SQL Server process, thereby compromising confidentiality, integrity, and availability of the affected database. The weakness is classified as CWE‑122, a classic memory corruption flaw that bypasses normal bounds checks.

Affected Systems

The flaw affects Microsoft SQL Server 2017 (CU 31, GDR) and Microsoft SQL Server 2019 (CU 32, GDR). These versions run on 64‑bit platforms, as identified by the associated CPE entries. The impact applies to any instance of these products that is reachable from an external network and lacks the current security update.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, but the KEV status shows the vulnerability is not currently known to be exploited in the wild. The description states that the overflow allows code execution over a network; therefore the attack requires network access to the SQL Server instance and an independent attacker who is not authenticated. Given the high CVSS, the risk is significant, especially in environments where the database is exposed to the internet or an untrusted network segment.

Generated by OpenCVE AI on September 10, 2026 at 02:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE‑2026‑77482 to all affected SQL Server 2017 and 2019 instances.
  • If patching cannot occur immediately, restrict inbound traffic to the SQL Server by configuring firewall rules or network segmentation so that only trusted hosts can reach the database ports.
  • After applying the fix, run a privileged security assessment to confirm that the process runs with the least‑privileged account and that role‑based access control limits database permissions to the minimum necessary for its function.

Generated by OpenCVE AI on September 10, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Sql Server 2017 Sql Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:25.291Z

Reserved: 2026-08-20T20:11:33.672Z

Link: CVE-2026-77482

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:56.409Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:33.770

Modified: 2026-09-15T16:09:51.460

Link: CVE-2026-77482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:00:09Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow