CVE-2026-72933
massHeap Buffer Overflow in Microsoft WDAC OLE DB Provider for SQL Enables RCE
CVE-2026-72933 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Data Access Components (WDAC) OLE DB provider for SQL, an in-box data-access component used by Windows applications to connect to SQL Server. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates a network vector with no privileges required but user interaction required, so an attacker would need a user to perform an action — such as opening attacker-crafted content or triggering a connection — that causes an application to pass attacker-controlled data through the vulnerable provider. Successful exploitation allows an unauthenticated attacker to execute arbitrary code in the context of the calling process, with high impact on confidentiality, integrity, and availability. Any Windows system whose applications use the WDAC SQL OLE DB provider to connect to SQL Server is potentially affected; the provided data does not specify exact affected version ranges. There is currently no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates roughly a 0.8% probability of exploitation within 30 days (56th percentile).
What to do: Apply Microsoft's security update for the WDAC OLE DB provider for SQL via Windows Update as soon as it is released, prioritizing hosts where applications use the SQL Server OLE DB provider in their connection strings. In the interim, limit user exposure of applications that use the provider against untrusted or attacker-influenceable SQL endpoints. Because the source data lacks version details, verify affected versions directly against Microsoft's advisory when patching.
| Microsoft WDAC OLE DB provider for SQL (Windows Data Access Components; in-box component used by applications connecting to SQL Se | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.