Executive brief
Microsoft SQL Server contains a heap-based buffer overflow vulnerability that allows an authorized attacker with network access to execute arbitrary code on the server. Successful exploitation could lead to complete compromise of the database server, including unauthorized access to sensitive data, service disruption, and potential lateral movement within the corporate network.
Technical details
A heap-based buffer overflow exists in Microsoft SQL Server that can be exploited by an authenticated attacker over the network to achieve remote code execution. The vulnerability is triggered by sending specially crafted network packets to the SQL Server instance. The attacker must be an authorized user with credentials to connect to the database server. Successful exploitation grants the attacker arbitrary code execution in the context of the SQL Server process, potentially allowing data exfiltration, denial of service, or further system compromise.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed