CVE-2026-67373
massHeap-Based Buffer Overflow in Microsoft SQL Server Enables Authenticated RCE
CVE-2026-67373 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server, assigned by Microsoft's CNA. An authorized attacker holding low-privilege credentials can trigger the flaw by sending crafted requests to SQL Server over the network, with no user interaction required. Successful exploitation permits arbitrary code execution in the SQL Server process context, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Organizations running Microsoft SQL Server are affected; the available data does not specify which versions or update branches are impacted, so defenders should consult Microsoft's advisory for the affected-version list. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.6% probability of exploitation within 30 days.
What to do: Apply Microsoft's SQL Server security update for CVE-2026-67373 as soon as the advisory identifies the affected versions and fixed builds. In the interim, restrict network exposure of SQL Server (e.g., port 1433) to trusted networks and review low-privilege logins that can reach the service, since exploitation requires authenticated access. Monitor Microsoft advisories and the KEV catalog for updates or emergence of public PoCs, which would raise exploitation risk.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.