Microsoft SQL Server Information Disclosure Vulnerability

Vulnerability

A vulnerability in Microsoft SQL Server allows unauthorized attackers to disclose information over a network by exploiting the use of uninitialized resources. This issue affects SQL Server 2019 and 2022.

Impact

Successful exploitation of this vulnerability could allow an attacker to view heap memory from a privileged process running on the server.

Remediation

Users can update to the latest cumulative or general distribution release security updates for SQL Server 2019 or 2022. Instructions for downloading these updates are available on the Microsoft Update Catalog.

Added: Jul 8, 2025, 7:05 PM
Updated: Jul 8, 2025, 7:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.