Heap-Based Buffer Overflow in Microsoft SQL Server
CVE-2026-77481
8.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-77481?
A heap-based buffer overflow vulnerability in Microsoft SQL Server enables an authorized attacker to execute arbitrary code remotely via the network. This can potentially compromise the integrity and security of affected SQL Server installations. Proper security measures and timely updates are essential to safeguard against exploitation of this vulnerability.
Affected Version(s)
Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3550.4
Microsoft SQL Server 2017 (GDR) x64-based Systems 14.0.0 < 14.0.2130.4
Microsoft SQL Server 2019 (CU 32) x64-based Systems 15.0.0.0 < 15.0.4490.9