Executive brief
Microsoft SQL Server contains an out-of-bounds read vulnerability that allows an authorized attacker to access sensitive information over the network. This could enable attackers with valid database credentials to extract confidential data, potentially compromising customer records, intellectual property, or other sensitive business information stored in the database.
Technical details
The vulnerability is an out-of-bounds read flaw in Microsoft SQL Server that permits information disclosure. An attacker with valid SQL Server authentication credentials can exploit this vulnerability over the network to read memory contents beyond intended boundaries, potentially exposing sensitive data. The attack requires prior authorization (valid login credentials) and network connectivity to the SQL Server instance. Patches are expected from Microsoft via their standard security update process.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed