ZeroHour

CVE-2026-72933

mass

Heap Buffer Overflow in Microsoft WDAC OLE DB Provider for SQL Enables RCE

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-72933 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Data Access Components (WDAC) OLE DB provider for SQL, an in-box data-access component used by Windows applications to connect to SQL Server. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates a network vector with no privileges required but user interaction required, so an attacker would need a user to perform an action — such as opening attacker-crafted content or triggering a connection — that causes an application to pass attacker-controlled data through the vulnerable provider. Successful exploitation allows an unauthenticated attacker to execute arbitrary code in the context of the calling process, with high impact on confidentiality, integrity, and availability. Any Windows system whose applications use the WDAC SQL OLE DB provider to connect to SQL Server is potentially affected; the provided data does not specify exact affected version ranges. There is currently no known in-the-wild exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates roughly a 0.8% probability of exploitation within 30 days (56th percentile).

What to do: Apply Microsoft's security update for the WDAC OLE DB provider for SQL via Windows Update as soon as it is released, prioritizing hosts where applications use the SQL Server OLE DB provider in their connection strings. In the interim, limit user exposure of applications that use the provider against untrusted or attacker-influenceable SQL endpoints. Because the source data lacks version details, verify affected versions directly against Microsoft's advisory when patching.

Affected
Microsoft WDAC OLE DB provider for SQL (Windows Data Access Components; in-box component used by applications connecting to SQL Se
Estimated exposure
mass>1,000,000 devices carry the in-box provider (Windows runs on ~1.4 billion devices per Microsoft); the functionally exposed subset is hosts running… — The provider ships in-box with supported Windows client and server releases, which Microsoft publicly reports at over one billion devices, but only systems whose applications actually connect to SQL Server through the OLE DB provider are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.