ZeroHour

CVE-2026-67385

mass

Use-After-Free RCE in Microsoft SQL Server

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-67385 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft SQL Server that allows an authorized attacker to execute arbitrary code over a network. An attacker with valid low-privilege credentials and network reachability to the SQL Server instance can send requests that trigger the freed-memory condition and gain code execution in the context of the SQL Server service. Successful exploitation yields high confidentiality, integrity, and availability impact on the target server (CVSS 3.1: 8.8). All organizations running affected SQL Server versions are potentially exposed, though the flaw requires authentication rather than anonymous access. There is currently no known public proof-of-concept, it is not listed in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.5%.

What to do: Consult Microsoft's advisory to identify the affected SQL Server versions/builds and apply the corresponding security update, prioritizing instances that are internet-exposed or reachable by broadly held low-privilege accounts. In the interim, restrict network access to SQL Server ports, enforce least-privilege authentication, and limit which accounts can connect remotely. Monitor Microsoft's guidance for exploitation updates, since a patch (or attacker interest) could change the picture quickly.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of installations worldwide (SQL Server is among the most widely deployed enterprise relational databases) — SQL Server has a very large installed base of millions of instances across enterprises and cloud deployments, and this is a ceiling estimate because the specific affected version ranges were not provided in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.