cve-2026-78442

HIGH CVSS 8.8 fkie_nvd
Description

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Affected Products
  • microsoft sql_server_2017
  • microsoft sql_server_2019
Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 2.8 5.9 secure@microsoft.com
CPE configurations
OR
CPE Version range Vulnerable
cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* < 14.0.2130.4 yes
cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* >= 14.0.3006.16, < 14.0.3550.4 yes
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* < 15.0.2190.7 yes
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* >= 15.0.4003.23, <= 15.0.4490.9 yes
NVD metadata
NVD status
Analyzed
Source identifier
secure@microsoft.com
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "affectedData": [
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SQL Server 2017 (CU 31)",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "14.0.3550.4",
              "status": "affected",
              "version": "14.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SQL Server 2017 (GDR)",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "14.0.2130.4",
              "status": "affected",
              "version": "14.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SQL Server 2019 (CU 32)",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "15.0.4490.9",
              "status": "affected",
              "version": "15.0.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SQL Server 2019 (GDR)",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "15.0.2190.7",
              "status": "affected",
              "version": "15.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*",
              "matchCriteriaId": "3207B09A-49E7-43D5-88B6-6ECF886B2E96",
              "versionEndExcluding": "14.0.2130.4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*",
              "matchCriteriaId": "E409F829-1995-4F4F-9103-F718E929C482",
              "versionEndExcluding": "14.0.3550.4",
              "versionStartIncluding": "14.0.3006.16",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*",
              "matchCriteriaId": "799073C2-2213-4F34-8F07-D6C10AC00578",
              "versionEndExcluding": "15.0.2190.7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*",
              "matchCriteriaId": "97DF0D00-9830-4818-9BC0-932A451F7228",
              "versionEndIncluding": "15.0.4490.9",
              "versionStartIncluding": "15.0.4003.23",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network."
    }
  ],
  "id": "CVE-2026-78442",
  "lastModified": "2026-09-23T15:36:54.890",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "NETWORK",
          "availabilityImpact": "HIGH",
          "baseScore": 8.8,
          "baseSeverity": "HIGH",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "scope": "UNCHANGED",
          "userInteraction": "REQUIRED",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "version": "3.1"
        },
        "exploitabilityScore": 2.8,
        "impactScore": 5.9,
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ],
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-78442",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "role": "CISA Coordinator",
          "timestamp": "2026-09-04T00:00:00+00:00",
          "version": "2.0.3"
        }
      }
    ]
  },
  "published": "2026-09-08T18:20:42.020",
  "references": [
    {
      "source": "secure@microsoft.com",
      "tags": [
        "Vendor Advisory",
        "Patch"
      ],
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78442"
    }
  ],
  "sourceIdentifier": "secure@microsoft.com",
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ],
      "source": "secure@microsoft.com",
      "type": "Secondary"
    }
  ]
}
Enrichment data
View JSON API Download JSON