Description
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation
Action: Patch Now
AI Analysis

Impact

A use‑after‑free flaw in Microsoft SQL Server’s internal memory handling allows an attacker who already has a local access to the database engine to elevate privileges within the machine. The vulnerability is triggered when the server attempts to access a memory region that has already been freed, leading to corruption of control data. If exploited, the attacker can gain higher OS‑level rights, potentially allowing full control of the host and access to other systems on the network.

Affected Systems

The flaw affects Microsoft SQL Server 2017 cumulative update 31 and its GDR release, SQL Server 2019 cumulative update 32 and its GDR, SQL Server 2022 cumulative update 26 and its GDR, and SQL Server 2025 cumulative update 8 and its GDR for x64‑based systems. These products are identified by the vendor as "Microsoft SQL Server" with the indicated release or cumulative update numbers.

Risk and Exploitability

The CVSS score of 7 indicates a moderate to high severity for a local privilege‑escalation flaw. The EPSS score is unavailable, so current exploitation probability is unknown, but there is no report of active exploitation in the CISA KEV catalog. The attack vector is otherwise inferred to be local, requiring that the attacker can run code or commands on the host that hosts the SQL Server instance. A successful exploitation would bestow elevated OS permissions on the attacker. No remote exploitation path appears to exist according to the description.

Generated by OpenCVE AI on September 9, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update for the affected SQL Server version from the Microsoft Security Update Guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77485).
  • If an immediate update is not possible, isolate the instance and restrict local account privileges to the minimum necessary to operate the database engine.
  • Continuously monitor audit logs for unexpected privilege changes or anomalous activities that could indicate exploitation.

Generated by OpenCVE AI on September 9, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Title SQL Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:01.908Z

Reserved: 2026-08-20T20:11:33.672Z

Link: CVE-2026-77485

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:40.618Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:34.147

Modified: 2026-09-15T16:07:35.373

Link: CVE-2026-77485

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:49:00Z

Weaknesses