CVE-2026-67378: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Other sources
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authorized and able to reach the SQL Server instance over the network. The available data does not identify the specific SQL Server permissions or role required.
Is user interaction required for exploitation?
No. The vector indicates that exploitation does not require user interaction once an authorized attacker has network access.
What is the potential impact of successful exploitation?
Successful exploitation can allow code execution and may result in high impacts to confidentiality, integrity, and availability. The scope is changed, indicating impacts may extend beyond the vulnerable SQL Server security authority.