Executive brief
Microsoft SQL Server contains a heap-based buffer overflow vulnerability that allows an authorized network attacker to execute arbitrary code. This could enable attackers with valid database credentials to gain complete control over SQL Server instances, potentially exposing or modifying sensitive business data stored in the database.
Technical details
A heap-based buffer overflow exists in SQL Server's memory management. The vulnerability is triggered during processing of specially crafted requests from authenticated users, allowing remote code execution with the privileges of the SQL Server service. The attacker must have valid SQL Server credentials to exploit this vulnerability. No additional user interaction is required once authenticated. Patches are available from Microsoft and should be applied immediately to affected systems.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed