Executive brief
Microsoft Fabric Data Warehouse, a cloud-based analytics platform, is affected by a security vulnerability that could allow an authorized user to execute unauthorized code. An attacker with basic access to the network could exploit this flaw to gain full control over the system, potentially leading to data theft or service disruption. Organizations using affected versions of Service Fabric should apply the latest security updates to protect their data environments.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in Microsoft Fabric Data Warehouse. The flaw is reachable over the network and requires low-level authenticated privileges (PR:L) to exploit. By sending specially crafted data to the affected component, an attacker can trigger the overflow to achieve remote code execution (RCE) with the privileges of the service. The vulnerability impacts Service Fabric versions from 1.0.0 up to 8.0.206.113. Microsoft has released updates to address this issue.
Affected products
- Microsoft Service Fabric 1.0.0 to 8.0.206.113
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD