Microsoft SQL Server Buffer Over-Read Vulnerability Allowing Information Disclosure

Vulnerability

A buffer over-read vulnerability has been identified in Microsoft SQL Server. This issue allows an authorized attacker to disclose information by reading small portions of heap memory over the network. The vulnerability affects several versions of SQL Server, including SQL Server 2025, 2022, 2019, and 2017, as well as SQL Server 2016 with the Azure Connect Feature Pack.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, allowing attackers to read sensitive data from memory.

Remediation

Users can apply the security update for their specific version of SQL Server. Detailed instructions for downloading and installing these security updates are available in the Microsoft SQL Server Security Update Guide. For SQL Server 2025, both GDR and CU6 update options are available. SQL Server instances on Windows Azure (IaaS) can also receive these security updates.

Added: Jul 14, 2026, 11:00 PM
Updated: Jul 14, 2026, 11:00 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
4.9
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.