CVE-2026-78442

Summary

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft SQL Server 2017 (CU 31)14.0.0 < 14.0.3550.4affected
MicrosoftMicrosoft SQL Server 2017 (GDR)14.0.0 < 14.0.2130.4affected
MicrosoftMicrosoft SQL Server 2019 (CU 32)15.0.0.0 < 15.0.4490.9affected
MicrosoftMicrosoft SQL Server 2019 (GDR)15.0.0 < 15.0.2190.7affected

Weaknesses

  • CWE-122: CWE-122: Heap-based Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References