Impact
A heap‑based buffer overflow in Microsoft SQL Server allows an attacker who has authorized access to execute arbitrary code remotely. The vulnerability is categorized as CWE‑122 and enables code execution on the database server, potentially compromising the confidentiality, integrity, and availability of the data stored within the instance.
Affected Systems
Microsoft SQL Server 2022, specifically the CU 26 release and the GDR (General Distribution Release) version for 64‑bit installations, is affected. The flaw is present only in the x64 build of the product as indicated by the CPE listing.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is unavailable but the lack of KEV listing suggests no widely known public exploit is yet reported. The likely attack vector is a network‑based, authorized attacker – the description indicates that the attacker must have database access privileges. Once exploited, the attacker can run arbitrary code on the host machine, giving full control over the affected server.
OpenCVE Enrichment