← Back to CVE List
CVE-2025-49717NVD
Vulnerability Summary
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVSS v3.1 Base Metrics — Score 8.5 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Microsoft Sql Server 2019 >= 15.0.2000.5 and < 15.0.2135.5
- Microsoft Sql Server 2019 >= 15.0.4003.23 and < 15.0.4435.7
- Microsoft Sql Server 2022 >= 16.0.1000.6 and < 16.0.1140.6
- Microsoft Sql Server 2022 >= 16.0.4003.1 and < 16.0.4200.1
- Microsoft Sql Server 2019 15.0.2135.5
- Microsoft Sql Server 2019 15.0.4435.7
- Microsoft Sql Server 2022 16.0.1140.6
- Microsoft Sql Server 2022 16.0.4200.1