ZeroHour

CVE-2026-77485

mass

Use-after-free privilege escalation in Microsoft SQL Server

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-77485 is a use-after-free vulnerability (CWE-416) in Microsoft SQL Server that allows an authorized attacker who already has low-privileged access on the affected machine to elevate privileges locally, so it is not a remote or unauthenticated flaw. The CVSS vector shows a local attack vector with high attack complexity and no user interaction, meaning successful exploitation depends on favorable memory-reuse conditions and may be difficult to carry out reliably. A successful attacker gains elevated privileges on the local host, with the vector indicating potentially high impact to confidentiality, integrity, and availability. Any organization running affected SQL Server builds is in scope, although the available data does not specify the affected version ranges, so defenders should consult Microsoft's advisory. As of this analysis there is no known exploitation, no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.2% over the next 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-77485 through your normal patch cycle, confirming affected builds against Microsoft's advisory since version ranges are not specified here. Given the high attack complexity, low EPSS (0.2%), and absence of known exploits or a public PoC, this can be treated as routine rather than emergency patching. In the interim, restrict local code-execution rights on SQL Server hosts to trusted accounts and prioritize patching multi-user servers and shared systems where local privilege escalation is most consequential.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of installations worldwide (SQL Server is a ubiquitous enterprise database; public internet scans routinely show hundreds of thousands of exposed… — The estimate is based on SQL Server's ubiquity in enterprise Windows environments (installations in the millions, with hundreds of thousands of instances visible in public internet scans), though the local attack vector means only hosts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.