CVE-2026-77485
massUse-after-free privilege escalation in Microsoft SQL Server
CVE-2026-77485 is a use-after-free vulnerability (CWE-416) in Microsoft SQL Server that allows an authorized attacker who already has low-privileged access on the affected machine to elevate privileges locally, so it is not a remote or unauthenticated flaw. The CVSS vector shows a local attack vector with high attack complexity and no user interaction, meaning successful exploitation depends on favorable memory-reuse conditions and may be difficult to carry out reliably. A successful attacker gains elevated privileges on the local host, with the vector indicating potentially high impact to confidentiality, integrity, and availability. Any organization running affected SQL Server builds is in scope, although the available data does not specify the affected version ranges, so defenders should consult Microsoft's advisory. As of this analysis there is no known exploitation, no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.2% over the next 30 days.
What to do: Apply the Microsoft security update addressing CVE-2026-77485 through your normal patch cycle, confirming affected builds against Microsoft's advisory since version ranges are not specified here. Given the high attack complexity, low EPSS (0.2%), and absence of known exploits or a public PoC, this can be treated as routine rather than emergency patching. In the interim, restrict local code-execution rights on SQL Server hosts to trusted accounts and prioritize patching multi-user servers and shared systems where local privilege escalation is most consequential.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.