Executive brief
Microsoft SQL Server contains a vulnerability in resource initialization that allows an attacker with database access to read sensitive information through network communication. This could expose confidential data such as configuration details, credentials, or business-critical information stored in the database, posing a risk to data confidentiality.
Technical details
The vulnerability is a use of uninitialized resource flaw in SQL Server that permits information disclosure over the network. An authorized attacker with legitimate database access can exploit this condition to extract sensitive data from memory or uninitialized buffers. The attack requires network connectivity to the SQL Server instance and valid database credentials. The vulnerability allows the attacker to read information that should not be accessible, though active exploitation has not been observed in the wild. A patch from Microsoft is expected to be available through standard security updates.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed