CVE-2026-32167: SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Other sources
SQL Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1110.1Patch KB5084814 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6485.1Patch KB5084821 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3525.1Patch KB5084818 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4465.1Patch KB5084816 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4030.1Patch KB5083245 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2105.1Patch KB5084819 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2165.1Patch KB5084817 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1175.1Patch KB5084815 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4250.1Patch KB5083252 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7080.1Patch KB5084820
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32167?
CVE-2026-32167 is classified as a critical elevation of privilege vulnerability affecting SQL Server.
How do I fix CVE-2026-32167?
To fix CVE-2026-32167, apply the latest cumulative updates or patches provided by Microsoft for your affected SQL Server version.
What versions of SQL Server are affected by CVE-2026-32167?
CVE-2026-32167 affects SQL Server 2016, 2017, 2019, and 2022, specifically with certain cumulative updates.
What are the risks associated with CVE-2026-32167?
The risks associated with CVE-2026-32167 include unauthorized access and potential elevation of privileges by attackers on SQL Server installations.
Can CVE-2026-32167 be exploited remotely?
CVE-2026-32167 allows local authorized attackers to exploit the vulnerability rather than remote exploitation.