ZeroHour

CVE-2026-77482

mass

Heap-Based Buffer Overflow RCE in Microsoft SQL Server

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-77482 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server that is reachable over a network by an unauthorized (unauthenticated) attacker. According to the CVSS vector, some user interaction (UI:R) is required to trigger the flaw, meaning an unwitting user action likely plays a role in exploitation, although no credentials are needed. A successful attack allows remote code execution, with the CVSS vector rating high impact on confidentiality, integrity, and availability. Any organization running an affected Microsoft SQL Server build is potentially affected, with internet-facing SQL Server endpoints at the greatest risk. As of the data available, there are no known public proofs of concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days (53rd percentile).

What to do: Monitor Microsoft's advisory for this CVE and install the security update it designates as soon as it is available, since the exact affected version ranges are not provided in this data. Until patched, restrict inbound network access to SQL Server (typically TCP 1433) to trusted hosts and networks, and avoid untrusted user interactions with SQL Server clients. Because exploitation requires user interaction per the CVSS vector, user awareness and least-privilege service configuration reduce practical risk.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of installations, with 100k+ SQL Server endpoints visible in public internet scans — Microsoft SQL Server is one of the most widely deployed enterprise databases (millions of instances), and public internet scans such as Shodan routinely index hundreds of thousands of exposed SQL Server endpoints, though only instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.