Junglewise Threat Intelligence

CVE-2026-72933: Microsoft WDAC OLE DB provider heap buffer overflow

CVE-2026-72933 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft's WDAC OLE DB provider for SQL Server is vulnerable to a heap-based buffer overflow that allows attackers to remotely execute code on affected systems without authentication. Exploitation could lead to complete system compromise, data theft, and lateral movement within corporate networks that rely on this database connectivity component.

Technical details

A heap-based buffer overflow exists in the Microsoft WDAC OLE DB provider for SQL Server. The vulnerability can be triggered remotely without prior authentication by sending specially crafted network packets. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the SQL Server process. The vulnerability is exploitable over the network, making it a high-impact remote code execution risk for any system exposing SQL Server connections to untrusted networks.

Affected products

  • Microsoft WDAC OLE DB provider for SQL

Timeline

  • 2026-09-08: disclosed

References