Executive brief
SQL Server is Microsoft's enterprise database platform used to store and manage business-critical data. An authorized database user can trigger an out-of-bounds memory read that exposes sensitive information, potentially leaking database contents or system memory across the network. This could compromise confidential customer or business data stored in the database.
Technical details
This vulnerability is an out-of-bounds read in Microsoft SQL Server that allows an authenticated attacker to read memory outside the bounds of allocated buffers. The attack requires valid database credentials and network access to the SQL Server instance. By exploiting this memory read vulnerability, an attacker can extract sensitive information from the SQL Server process memory and transmit it over the network. The exact vulnerable component and root cause are not detailed in the reference material provided.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed