Executive brief
SQL Server, a database platform used by many organizations to store and manage critical business data, contains a memory access vulnerability. An authenticated attacker with network access could exploit this flaw to read unauthorized information from the database server's memory, potentially exposing sensitive customer or operational data.
Technical details
This vulnerability is an out-of-bounds read in Microsoft SQL Server that allows an authenticated network attacker to disclose information. The attack requires valid database credentials and network connectivity to the SQL Server instance. By exploiting the memory access flaw, an attacker can read beyond allocated buffer boundaries to access sensitive data in server memory. The vulnerability has a CVSS score of 6.5 (medium severity) and is not currently known to be exploited in the wild. Microsoft has released security updates to address this issue.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed