Description
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap-based buffer overflow exists in the Windows OLE DB provider, enabling attackers to supply crafted input that corrupts the receive buffer and allows execution of arbitrary code. The vulnerability is accessed over the network against the OLE DB service used by Microsoft SQL Server, providing a clear path for remote exploitation. The weakness is classified as CWE-122, which can lead to compromise of the SQL Server process and underlying host.

Affected Systems

Microsoft SQL Server 2017 versions CU 31 and GDR, and Microsoft SQL Server 2019 versions CU 32 and GDR, all on x64 platforms.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploit data is scarce but the risk remains significant due to the nature of remote code execution. The likely attack vector is remote network access to the OLE DB service; an attacker can send malicious requests from an unauthenticated perspective to trigger the overflow and execute code on the server.

Generated by OpenCVE AI on September 9, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the cumulative update or GDR for the affected SQL Server releases using the instructions in the Microsoft update guide linked in the advisory.
  • Restart the SQL Server services to activate the patch.
  • If the OLE DB provider is not required, disable or remove it from the SQL Server instance.
  • Configure firewall or network segmentation controls to restrict access to the OLE DB service exclusively to trusted IP ranges.

Generated by OpenCVE AI on September 9, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
Title Windows OLE DB Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (gdr) Sql Server 2017 Sql Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:06.251Z

Reserved: 2026-08-24T16:21:50.286Z

Link: CVE-2026-78442

cve-icon Vulnrichment

Updated: 2026-09-08T19:23:02.887Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:42.020

Modified: 2026-09-23T15:36:54.890

Link: CVE-2026-78442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T00:15:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow