Executive brief
Microsoft SQL Server is a widely used database management system for storing and processing corporate data. A vulnerability has been identified that allows an authorized user to execute malicious code on the server over the network. This could lead to a complete compromise of the database server, resulting in unauthorized data access, data loss, or service disruption.
Technical details
A vulnerability exists in Microsoft SQL Server due to an untrusted pointer dereference (CWE-822). An attacker with low-privileged credentials can exploit this flaw over a network connection without any user interaction. Successful exploitation allows for remote code execution in the context of the SQL Server service. The vulnerability affects multiple versions including SQL Server 2016 through 2025. Microsoft has released security updates to address this issue across the affected versions.
Affected products
- Microsoft SQL Server 2016 13.0.6300.2 - 13.0.6485.1, 13.0.7000.253 - 13.0.7080.1
- Microsoft SQL Server 2017 14.0.1000.169 - 14.0.2105.1, 14.0.3006.16 - 14.0.3525.1
- Microsoft SQL Server 2019 15.0.2000.5 - 15.0.2165.1, 15.0.4003.23 - 15.0.4465.1
- Microsoft SQL Server 2022 16.0.1000.6 - 16.0.1175.1, 16.0.4003.1 - 16.0.4250.1
- Microsoft SQL Server 2025 17.0.1000.7 - 17.0.1110.1, 17.0.4006.2 - 17.0.4030.1
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Microsoft released the security update guide for this vulnerability.