Impact
This vulnerability is a heap‑based buffer overflow that can be triggered by an unauthorized attacker using a crafted payload delivered over the network. When successfully exploited, the attacker can execute arbitrary code with the privileges of the SQL Server process, thereby compromising confidentiality, integrity, and availability of the affected database. The weakness is classified as CWE‑122, a classic memory corruption flaw that bypasses normal bounds checks.
Affected Systems
The flaw affects Microsoft SQL Server 2017 (CU 31, GDR) and Microsoft SQL Server 2019 (CU 32, GDR). These versions run on 64‑bit platforms, as identified by the associated CPE entries. The impact applies to any instance of these products that is reachable from an external network and lacks the current security update.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, but the KEV status shows the vulnerability is not currently known to be exploited in the wild. The description states that the overflow allows code execution over a network; therefore the attack requires network access to the SQL Server instance and an independent attacker who is not authenticated. Given the high CVSS, the risk is significant, especially in environments where the database is exposed to the internet or an untrusted network segment.
OpenCVE Enrichment