Impact
A heap-based buffer overflow exists in the Windows OLE DB provider, enabling attackers to supply crafted input that corrupts the receive buffer and allows execution of arbitrary code. The vulnerability is accessed over the network against the OLE DB service used by Microsoft SQL Server, providing a clear path for remote exploitation. The weakness is classified as CWE-122, which can lead to compromise of the SQL Server process and underlying host.
Affected Systems
Microsoft SQL Server 2017 versions CU 31 and GDR, and Microsoft SQL Server 2019 versions CU 32 and GDR, all on x64 platforms.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploit data is scarce but the risk remains significant due to the nature of remote code execution. The likely attack vector is remote network access to the OLE DB service; an attacker can send malicious requests from an unauthenticated perspective to trigger the overflow and execute code on the server.
OpenCVE Enrichment