Impact
A flaw allowing the deserialization of data supplied from untrusted sources in Microsoft SQL Server can be leveraged by an attacker who already has legitimate access rights to perform arbitrary code execution on the database host. This weakness is a classic example of insecure deserialization, identified as CWE‑502. Exploiting it removes any boundaries that normally separate database operations from the operating system, enabling the attacker to gain full control over the underlying server.
Affected Systems
Microsoft SQL Server 2019 (Cumulative Update 32 and GDR), Microsoft SQL Server 2022 (Cumulative Update 26 and GDR), and Microsoft SQL Server 2025 (Cumulative Update 8 and GDR) on x‑64 architectures.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating a high risk of exploitation without advanced prerequisites beyond legitimate credentials. The EPSS score is 1%, yet the lack of listing in the CISA KEV database does not diminish the potential impact. An attacker who can reach the SQL Server instance over the network and possess authorized credentials can trigger the flaw to execute code remotely, potentially compromising the entire host and any connected systems.
OpenCVE Enrichment