Junglewise Threat Intelligence

CVE-2026-77485: Microsoft SQL Server use after free privilege escalation

CVE-2026-77485 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Microsoft SQL Server contains a use-after-free vulnerability that allows an authorized local user to escalate their privileges on the system. An attacker with valid SQL Server credentials could exploit this flaw to gain elevated access, potentially compromising sensitive data or taking control of the database server.

Technical details

A use-after-free vulnerability exists in Microsoft SQL Server that can be exploited by an authenticated attacker with local access to elevate privileges. The vulnerability stems from improper memory management in a component that processes user-supplied input. An attacker who has valid credentials to SQL Server and local system access can trigger the use-after-free condition to execute arbitrary code with elevated privileges. This vulnerability requires authentication and local network access to exploit.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats