ZeroHour

CVE-2026-77487

mass

Authenticated Privilege Escalation in Microsoft SQL Server

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
AI analysis

Microsoft SQL Server contains an improper access control flaw (CWE-284) that allows an authorized, low-privileged user to elevate privileges over the network. Exploitation requires only existing low-level credentials and network reachability to the SQL Server instance; no user interaction or local access is needed (AV:N, PR:L, UI:N). An attacker who succeeds gains elevated privileges with high impact on confidentiality, integrity, and availability of the database (CVSS 3.1: 8.8 High). Organizations running Microsoft SQL Server are affected; the available data does not specify which versions or update levels are impacted, so defenders should consult Microsoft's advisory for affected-release details. As of this writing there is no known exploitation, no public proof-of-concept, and the flaw is not in the CISA KEV catalog, with EPSS estimating roughly a 0.5% probability of exploitation in the next 30 days (44th percentile).

What to do: Apply Microsoft's SQL Server security update for this CVE once published, using the version-specific guidance in the MSRC advisory, since affected version ranges are not specified in the available data. In the interim, restrict network exposure of SQL Server (especially TCP 1433 on internet-facing hosts), audit which low-privileged logins and accounts can connect to each instance, and enforce least-privilege role assignments. Prioritize patching instances that are reachable from untrusted networks or shared multi-tenant environments where low-privileged users exist.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of installations; hundreds of thousands of instances internet-exposed (public scans) — Microsoft SQL Server is one of the most widely deployed enterprise databases, and public internet scans consistently show hundreds of thousands of SQL Server instances listening on TCP 1433, in addition to the far larger population of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.