Untrusted Pointer Dereference in SQL Server by Microsoft
CVE-2026-33120
8.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-33120?
A vulnerability exists in Microsoft SQL Server that enables an authorized attacker to exploit an untrusted pointer dereference, potentially allowing remote code execution over the network. This poses a significant risk as it can enable attackers to gain unauthorized control over affected systems. Users are advised to review the security updates and apply necessary patches to safeguard their environments.
Affected Version(s)
Microsoft SQL Server 2022 (GDR) x64-based Systems 16.0.0 < 16.0.1175.1