Executive brief
Microsoft SQL Server contains a heap-based buffer overflow vulnerability that can be exploited by an authorized attacker with network access to execute arbitrary code. This allows an attacker with valid database credentials to compromise the server, potentially leading to data theft, service disruption, or lateral movement within the network.
Technical details
A heap-based buffer overflow exists in Microsoft SQL Server that can be triggered by an authorized attacker over the network. The vulnerability requires valid authentication credentials and network reachability to the SQL Server instance. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the SQL Server process, potentially leading to complete server compromise. A patch is available from Microsoft through their Security Update Guide.
Affected products
- Microsoft SQL Server
Timeline
- 2026-09-08: disclosed