Heap-based Buffer Overflow in Windows OLE DB by Microsoft
CVE-2026-78442

8.8HIGH

What is CVE-2026-78442?

A heap-based buffer overflow in Windows OLE DB allows attackers to exploit the vulnerability via crafted network requests, potentially executing arbitrary code and compromising system integrity. This security flaw highlights the importance of maintaining up-to-date software and applying patches promptly to mitigate risks.

Affected Version(s)

Microsoft SQL Server 2017 (CU 31) x64-based Systems 14.0.0 < 14.0.3550.4

Microsoft SQL Server 2017 (GDR) x64-based Systems 14.0.0 < 14.0.2130.4

Microsoft SQL Server 2019 (CU 32) x64-based Systems 15.0.0.0 < 15.0.4490.9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.