Junglewise Threat Intelligence

CVE-2026-67379: Microsoft SQL Server stack-based buffer overflow

CVE-2026-67379 · Severity: high · CVSS 8.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

Microsoft SQL Server contains a stack-based buffer overflow vulnerability that allows an authenticated attacker to execute arbitrary code on the server remotely. This could enable attackers with database credentials to compromise the SQL Server and access or manipulate sensitive data, or use it as a foothold to attack other systems on the network.

Technical details

A stack-based buffer overflow exists in Microsoft SQL Server that can be exploited by an authorized attacker with network access to the database. The vulnerability allows code execution on the affected server when memory is overflowed during processing. As this requires prior authentication and network connectivity to SQL Server, the attack vector is limited to users or services that already have database credentials. Successful exploitation grants arbitrary code execution in the SQL Server process context, potentially allowing data theft, modification, or use as a pivot point for further compromise. Microsoft has published a security update to address this vulnerability (CVE-2026-67379).

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats