Impact
Integer overflow or wraparound in Microsoft SQL Server allows an unauthorized attacker to execute arbitrary code. The flaw arises when the database engine fails to properly validate arithmetic limits, enabling a malicious input to corrupt internal data structures and gain control of execution flow.
Affected Systems
The vulnerability affects Microsoft SQL Server 2017 on its Cumulative Update 31 or the GDR release, and Microsoft SQL Server 2019 on its Cumulative Update 32 or the GDR release. Only the 64‑bit editions are impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability that allows remote code execution. No EPSS score is currently available and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based, as the description explicitly states that the attacker can exploit the flaw over a network connection. Successful exploitation would grant the attacker full control over the affected SQL Server instance.
OpenCVE Enrichment