CVE-2026-67643
massAuthenticated RCE via heap buffer overflow in Microsoft SQL Server
Microsoft SQL Server contains a heap-based buffer overflow (CWE-122) that can be triggered over a network by an authorized attacker, with the CVSS vector indicating that only low-privileged credentials are required (AV:N/AC:L/PR:L). Successful exploitation lets the attacker execute code on the host running SQL Server, with high impact to confidentiality, integrity, and availability. Because authentication is required, risk concentrates on instances reachable from networks where an attacker holds valid SQL logins, including internet-exposed servers and systems accessible across trust boundaries. Any organization running an affected SQL Server build (per Microsoft's advisory) is potentially affected. There is currently no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates a 0.8% probability of exploitation within 30 days.
What to do: Consult Microsoft's advisory to identify affected SQL Server builds and editions and apply the corresponding security update, prioritizing instances that are internet-facing or reachable from untrusted network segments. Until patched, restrict network access to SQL Server ports (e.g., TCP 1433) from untrusted networks and audit which low-privileged accounts hold remote SQL logins that could be used for authentication.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2022, sql server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.