Executive brief
Microsoft SQL Server contains a flaw that allows an authorized user to read memory beyond intended boundaries, potentially exposing sensitive data. An attacker with database access can exploit this over the network to retrieve confidential information from the server's memory, compromising data confidentiality.
Technical details
A out-of-bounds read vulnerability exists in SQL Server that allows an authenticated attacker to access memory regions outside the intended data structures. The vulnerability requires network access to the SQL Server instance and valid database credentials. By crafting specific requests, an attacker can trigger the out-of-bounds read to leak sensitive information from server memory. The vulnerability has a CVSS score of 6.5 (medium severity) and requires authentication as a precondition for exploitation.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed