Impact
This vulnerability is an improper access control flaw (CWE‑284) that allows an attacker who already has network access to a SQL Server instance to elevate their privileges and perform actions normally restricted to higher‑level users.
Affected Systems
Affected products are Microsoft SQL Server 2017 CU 31 and GDR, SQL Server 2019 CU 32 and GDR, SQL Server 2022 CU 26 and GDR, and SQL Server 2025 CU 8 along with its GDR for 64‑bit systems.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, placing it in the high‑severity range. Exploitation requires an authenticated attacker with access to the SQL Server network interface, so the attack vector is most likely over a network connection to the server. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating no publicly known exploits at this time, yet the high impact warrants prompt attention.
OpenCVE Enrichment