Executive brief
SQL Server can generate error messages that inadvertently expose sensitive information. An authorized attacker with network access could exploit this to extract confidential data through error responses, potentially compromising database credentials, configuration details, or other sensitive operational information.
Technical details
This vulnerability exists in SQL Server's error handling mechanism, which generates error messages containing sensitive information that should not be disclosed. The vulnerability is triggered during network communication and requires an attacker to be authorized to connect to SQL Server. By crafting specific queries or requests that generate errors, an attacker can extract sensitive data from the error message responses. No public exploit code is known to be in active circulation. Microsoft has released security updates to address this issue.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed