Executive brief
SQL Server is a database platform used to store and manage critical business data. An authorized user can exploit an out-of-bounds read vulnerability to extract sensitive information from the database system over the network, potentially exposing confidential records or system configuration details.
Technical details
An out-of-bounds read vulnerability exists in Microsoft SQL Server that allows an authenticated attacker to disclose information over a network. The vulnerability requires the attacker to be an authorized user with network access to the SQL Server instance. By crafting a specific query or request, the attacker can trigger the out-of-bounds read condition, causing the server to return sensitive memory contents or data that should not be accessible. The issue has been assigned CVSS 6.5 (medium severity) and does not require elevated privileges beyond standard authenticated access.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed