CVE-2026-77482: Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775
Event History
Frequently Asked Questions
Does exploitation require SQL Server credentials?
No. The attack vector indicates no privileges are required, so an unauthorized attacker can attempt exploitation over the network.
Is user interaction required for exploitation?
Yes. The severity vector indicates that user interaction is required.
What is the expected impact if exploitation succeeds?
The vulnerability is rated high impact for confidentiality, integrity, and availability, with the impact scope unchanged.
Which SQL Server releases are identified in the affected software list?
The affected software list includes Microsoft SQL Server 2017, including CU 31, and Microsoft SQL Server 2019, including CU 32.