Junglewise Threat Intelligence

CVE-2026-42990: Microsoft SQL Server ODBC Driver heap overflow remote code execution

CVE-2026-42990 · Severity: critical · CVSS 9.8 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

A critical vulnerability exists in the Microsoft SQL Server ODBC driver, a component used by many applications to communicate with databases. An attacker could exploit this flaw over a network to gain full control of an affected system without needing any user interaction or login credentials. This poses a severe risk to data confidentiality and system availability, potentially leading to unauthorized data access or complete service disruption.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Microsoft SQL Server ODBC driver. The vulnerability is triggered when the driver processes specially crafted network packets, leading to memory corruption. An unauthenticated attacker can exploit this over the network (AV:N) with low complexity (AC:L) and no user interaction (UI:N) to achieve remote code execution (RCE). The flaw affects various versions of Windows 10 and Windows 11 where the driver is installed. Microsoft has released security updates to address this issue; users should apply the July 2026 patches.

Affected products

  • Microsoft SQL Server ODBC Driver Windows 10, Windows 11, Windows Server versions prior to July 2026 updates

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References