Executive brief
SQL Server is a widely-deployed database platform used across enterprises to store and manage critical business data. A vulnerability in how SQL Server resolves file links allows an authenticated attacker with network access to bypass security controls and gain elevated privileges, potentially leading to unauthorized access to sensitive data or system compromise.
Technical details
The vulnerability is a link following (improper link resolution before file access) flaw in SQL Server. An authorized attacker with network connectivity to an affected SQL Server instance can exploit this to escalate their privileges. The flaw allows an attacker to manipulate file path resolution to access resources they should not have permission to reach. This is a network-accessible privilege escalation requiring valid authentication to the SQL Server instance. A patch from Microsoft is expected to be available through standard security updates.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed