Executive brief
Microsoft SQL Server contains an out-of-bounds memory read vulnerability that allows authenticated attackers to cause a denial of service (application crash) over the network. An attacker with valid database credentials can trigger the vulnerability to disrupt SQL Server operations and impact business continuity.
Technical details
An out-of-bounds read vulnerability exists in Microsoft SQL Server that can be triggered by an authenticated attacker over the network. The vulnerability stems from improper bounds checking in memory access operations, allowing an attacker to read beyond allocated buffer boundaries. Exploitation requires valid authentication credentials and network connectivity to the SQL Server instance. Successful exploitation results in a denial of service condition (crash or hang). A patch is expected from Microsoft as indicated by the published MSRC advisory.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed