CVE-2026-67373: Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected SQL Server instance. Exploitation can be performed over a network and does not require user interaction.
What is the potential impact of successful exploitation?
Successful exploitation allows the attacker to execute code on the affected SQL Server. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
Which deployments are identified as affected?
The affected software list identifies Microsoft SQL Server 2025 and Microsoft SQL Server 2025 (CU8).