CVE-2026-77482
massHeap-Based Buffer Overflow RCE in Microsoft SQL Server
CVE-2026-77482 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server that is reachable over a network by an unauthorized (unauthenticated) attacker. According to the CVSS vector, some user interaction (UI:R) is required to trigger the flaw, meaning an unwitting user action likely plays a role in exploitation, although no credentials are needed. A successful attack allows remote code execution, with the CVSS vector rating high impact on confidentiality, integrity, and availability. Any organization running an affected Microsoft SQL Server build is potentially affected, with internet-facing SQL Server endpoints at the greatest risk. As of the data available, there are no known public proofs of concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days (53rd percentile).
What to do: Monitor Microsoft's advisory for this CVE and install the security update it designates as soon as it is available, since the exact affected version ranges are not provided in this data. Until patched, restrict inbound network access to SQL Server (typically TCP 1433) to trusted hosts and networks, and avoid untrusted user interactions with SQL Server clients. Because exploitation requires user interaction per the CVSS vector, user awareness and least-privilege service configuration reduce practical risk.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.