Impact
This vulnerability arises from weak authentication mechanisms within Microsoft SQL Server. An attacker who already has authorized access over the network can exploit the flaw to elevate privileges, potentially gaining administrative rights on the database server. The weakness can be categorized under CWE-1390, reflecting improper use of cryptographic checks which enables unauthorized privilege escalation.
Affected Systems
Affected products include multiple Microsoft SQL Server releases: 2017 (Cumulative Update 31 and GDR), 2019 (CU 32 and GDR), 2022 (CU 26 and GDR), and 2025 (CU 8 and the x64 GDR). All variants are 64‑bit deployments.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level. While no EPSS score is currently available, the lack of listing in CISA's KEV catalog does not diminish the risk, especially for environments that are exposed to a network. The vulnerability requires a trusted attacker to be on the same network and to possess initial authentication; once present, the attacker can elevate privileges without further exploitation steps. This combination of a moderately high severity rating and the requirement of network access makes it a significant threat for on‑premise or cloud‑hosted SQL Server instances.
OpenCVE Enrichment