ZeroHour

CVE-2026-67384

mass

Integer Overflow Remote Code Execution in Microsoft SQL Server

CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-67384 is an integer overflow or wraparound flaw (CWE-190, listed alongside CWE-122 memory corruption) in Microsoft SQL Server, rated High severity at CVSS 8.8. It is triggered over the network by an authorized attacker: the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates that any account with the ability to connect to and send requests to the SQL Server service can reach the vulnerable code path, with no user interaction required. Successful exploitation yields remote code execution in the context of the SQL Server service, with high impact on confidentiality, integrity, and availability. Any organization running Microsoft SQL Server is potentially affected, although the source data does not specify which version ranges are impacted. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 0.6% probability of exploitation within 30 days, so no exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-67384 as soon as it is released, and check Microsoft's advisory for the exact affected versions since they are not listed in this data. Until patched, limit network exposure of SQL Server instances (firewall/NSG rules, VPN-only or internal-only access) and review which accounts hold remote login rights, since exploitation requires authorized credentials. Monitor Microsoft communications for updated exploit or exploitation status.

Affected
Microsoft SQL Server
Estimated exposure
masson the order of millions of SQL Server instances worldwide (broad enterprise install base); per-version counts unknown — Microsoft SQL Server is one of the most widely deployed relational database platforms with an install base measured in millions of instances globally per public market-share surveys, though the affected version ranges here are unspecified…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.