CVE-2026-78441: Windows OLE DB Information Disclosure Vulnerability
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
Other sources
Windows OLE DB Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772
Event History
Frequently Asked Questions
Which SQL Server deployments are identified as affected?
The listed affected software includes Microsoft SQL Server 2017, SQL Server 2017 CU 31, SQL Server 2019, and SQL Server 2019 CU 32.
Does exploitation require attacker credentials or local access?
The vector indicates network access and no privileges are required. It also indicates user interaction is required.
What is the expected security impact?
The supplied vector rates confidentiality impact as high, with no indicated integrity or availability impact. The issue is rated medium severity with a 6.5 base score.