Impact
Out-of-bounds read in Windows OLE DB enables unauthorized network attackers to read sensitive memory contents. The vulnerability can lead to disclosure of confidential database information, compromising confidentiality. It is classified as an out‑of‑bounds read (CWE‑125).
Affected Systems
Affected systems include Microsoft SQL Server 2017 versions through CU 31 and the GDR, and Microsoft SQL Server 2019 versions through CU 32 and the GDR, running on 64‑bit architectures.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw over the network by sending crafted OLE DB requests without authentication, which suggests a remote, network‑based vector and a moderate likelihood of exploitation in environments with exposed SQL Server endpoints.
OpenCVE Enrichment