Impact
A use‑after‑free flaw in Microsoft SQL Server’s internal memory handling allows an attacker who already has a local access to the database engine to elevate privileges within the machine. The vulnerability is triggered when the server attempts to access a memory region that has already been freed, leading to corruption of control data. If exploited, the attacker can gain higher OS‑level rights, potentially allowing full control of the host and access to other systems on the network.
Affected Systems
The flaw affects Microsoft SQL Server 2017 cumulative update 31 and its GDR release, SQL Server 2019 cumulative update 32 and its GDR, SQL Server 2022 cumulative update 26 and its GDR, and SQL Server 2025 cumulative update 8 and its GDR for x64‑based systems. These products are identified by the vendor as "Microsoft SQL Server" with the indicated release or cumulative update numbers.
Risk and Exploitability
The CVSS score of 7 indicates a moderate to high severity for a local privilege‑escalation flaw. The EPSS score is unavailable, so current exploitation probability is unknown, but there is no report of active exploitation in the CISA KEV catalog. The attack vector is otherwise inferred to be local, requiring that the attacker can run code or commands on the host that hosts the SQL Server instance. A successful exploitation would bestow elevated OS permissions on the attacker. No remote exploitation path appears to exist according to the description.
OpenCVE Enrichment