Critical severity
2
Rated by Microsoft
SQL Server security
Search Microsoft SQL Server CVEs, affected releases, servicing branches, security-update builds, KB articles, and MSRC exploitation status. Open a record to find the CU, GDR, or service-pack update path that matches your server.
Every vulnerability record on this page comes from Microsoft Security Response Center. MSRC supplies the CVE details, revision history, affected update paths, builds after update, and security-update links.
After you identify the applicable security update, use the SQL Server updates list to verify its place in the CU or GDR history and the SQL Server patching guide to plan the change.
Catalog summary
These counts summarize the current MSRC catalog by severity, release date, and public disclosure. Open the CVE list to check an individual record against your SQL Server product, servicing path, and installed build.
Critical severity
2
Rated by Microsoft
Released in 2025 or 2026
34
Recent Microsoft records
Publicly disclosed
5
Marked public by Microsoft
SQL Server CVE list
Newest Microsoft revisions appear first. Search by CVE, SQL Server release, servicing branch, update build, KB article, severity, or impact. Open a result to see Microsoft update paths, builds after update, revision notes, and the original record.
Microsoft places Reporting Services and some related data products in the SQL Server product family. Confirm the exact affected-product row before choosing an update.
Showing 18 of 253 matching records
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3540.1 | KB 5102337Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2120.1 | KB 5102338Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7095.1 | KB 5102339Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6500.1 | KB 5102340Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 25) | 16.0.4262.2 | KB 5101347Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1190.2 | KB 5102334Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4480.2 | KB 5102335Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2180.2 | KB 5102336Download |
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2120.1 | KB 5102338Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6500.1 | KB 5102340Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 25) | 16.0.4262.2 | KB 5101347Download |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4480.2 | KB 5102335Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3540.1 | KB 5102337Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1190.2 | KB 5102334Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2180.2 | KB 5102336Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7095.1 | KB 5102339Download |
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4480.2 | KB 5102335Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1190.2 | KB 5102334Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3540.1 | KB 5102337Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7095.1 | KB 5102339Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6500.1 | KB 5102340Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2180.2 | KB 5102336Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2120.1 | KB 5102338Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 25) | 16.0.4262.2 | KB 5101347Download |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2025 for x64-based Systems (CU6) | 17.0.4060.2 | KB 5101346Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 25) | 16.0.4262.2 | KB 5101347Download |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4480.2 | KB 5102335Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1125.2 | KB 5102333Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1190.2 | KB 5102334Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3540.1 | KB 5102337Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7095.1 | KB 5102339Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6500.1 | KB 5102340Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2180.2 | KB 5102336Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2120.1 | KB 5102338Download |
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
Microsoft lists this CVE under SQL Server, but the affected-product table is unavailable.
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Power BI Report Server | 15.0.1121.120 | KB Release NotesDownload |
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Fabric Data Warehouse | 8.0.206.113 | KB Release NotesDownload |
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4470.1 | KB 5090407Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1115.1 | KB 5091223Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1180.1 | KB 5091158Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3530.2 | KB 5090354Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7085.1 | KB 5089270Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6490.1 | KB 5089271Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2170.1 | KB 5090408Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2110.2 | KB 5090347Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 24) | 16.0.4252.3 | KB 5089900Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU4) | 17.0.4040.1 | KB 5089899Download |
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1175.1 | KB 5084815Download |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4465.1 | KB 5084816Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1175.1 | KB 5084815Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3525.1 | KB 5084818Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7080.1 | KB 5084820Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6485.1 | KB 5084821Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2165.1 | KB 5084817Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2105.1 | KB 5084819Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 24) | 16.0.4250.1 | KB 5083252Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1110.1 | KB 5084814Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU3) | 17.0.4030.1 | KB 5083245Download |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2022 for x64-based Systems (CU 24) | 16.0.4250.1 | KB 5083252Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU3) | 17.0.4030.1 | KB 5083245Download |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4465.1 | KB 5084816Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1110.1 | KB 5084814Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3525.1 | KB 5084818Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1175.1 | KB 5084815Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7080.1 | KB 5084820Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6485.1 | KB 5084821Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2105.1 | KB 5084819Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2165.1 | KB 5084817Download |
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Microsoft revision
Version 1.2. Updated CWE value. This is an informational change only.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft PowerBI for iOS | 1.2.260302.2193910 | KB Release NoteDownload |
| Microsoft PowerBI for Android | 2.2.260210.21290750 | KB Release NoteDownload |
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2025 for x64-based Systems (CU2) | 17.0.4020.2 | KB 5077466Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1105.2 | KB 5077468Download |
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7075.5 | KB 5077473Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2160.4 | KB 5077470Download |
| Microsoft SQL Server 2025 for x64-based Systems (CU2) | 17.0.4020.2 | KB 5077466Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 23) | 16.0.4240.4 | KB 5077464Download |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4460.4 | KB 5077469Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1170.5 | KB 5077465Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3520.4 | KB 5077471Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6480.4 | KB 5077474Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2100.4 | KB 5077472Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1105.2 | KB 5077468Download |
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Microsoft revision
Version 1. Information published.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected releases and Microsoft updates
MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.
| Release / update path | Build after update | Security update |
|---|---|---|
| Microsoft SQL Server 2025 for x64-based Systems (CU2) | 17.0.4020.2 | KB 5077466Download |
| Microsoft SQL Server 2022 for x64-based Systems (CU 23) | 16.0.4240.4 | KB 5077464Download |
| Microsoft SQL Server 2019 for x64-based Systems (CU 32) | 15.0.4460.4 | KB 5077469Download |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1105.2 | KB 5077468Download |
| Microsoft SQL Server 2022 for x64-based Systems (GDR) | 16.0.1170.5 | KB 5077465Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | 13.0.7075.5 | KB 5077473Download |
| Microsoft SQL Server 2017 for x64-based Systems (CU 31) | 14.0.3520.4 | KB 5077471Download |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | 13.0.6480.4 | KB 5077474Download |
| Microsoft SQL Server 2019 for x64-based Systems (GDR) | 15.0.2160.4 | KB 5077470Download |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | 14.0.2100.4 | KB 5077472Download |
Check your server
Start with the installed build. Product names such as SQL Server 2022 are too broad because Microsoft ships separate fixes for different servicing branches.
Run this read-only query on each SQL Server instance. Availability Group replicas and cluster nodes can have different builds during maintenance.
SELECT
SERVERPROPERTY('ProductVersion')
AS ProductVersion,
SERVERPROPERTY('ProductLevel')
AS ProductLevel,
SERVERPROPERTY('Edition')
AS Edition;Open the CVE and find the CU, GDR, service-pack, or feature-pack row that matches the installed SQL Server release.
The MSRC base product version is not an affected-build boundary. Use the linked KB to confirm which earlier builds can take that update.
After patching, confirm that ProductVersion matches or exceeds the build published by Microsoft for the selected update path.
Treat an exploited CVE as urgent. You still need the correct CU or GDR, a backup and rollback plan, and a tested validation check. Continue with the SQL Server updates list and patching guide.
Data source
The Microsoft Security Response Center (MSRC) publishes Microsoft's vulnerability advisories and Security Update Guide. It records which products are affected and which security updates address them.
This tracker reads its CVEs, revisions, severity ratings, affected update paths, builds, exploitation flags, and KB links from MSRC. Open the Microsoft record before patching because affected products and guidance can change after publication.
Microsoft CVE details, revision history, severity, affected update paths, security-update builds, and KB links.
Status
Checked
Records
253 CVEs
Microsoft Security Response Center is the source for this SQL Server CVE tracker. Its records provide revision history, severity, affected update paths, builds installed by each security update, exploitation status, and Knowledge Base links.
Get the ProductVersion, ProductLevel, and edition from the server. Identify its CU, GDR, or service-pack path, then open the matching Microsoft KB and check the prerequisites. A release year or MSRC base product version alone is too broad to confirm exposure.
It means MSRC marks the vulnerability as exploited. Treat it as a prioritization flag, then confirm the affected product, build, attack conditions, and applicable Microsoft security update.
No. CVSS describes technical severity. Exposure depends on the affected SQL Server product, installed build, configuration, access path, and the conditions described in the Microsoft advisory.
The Last checked date shows when MSRC was most recently read. Newest Microsoft revisions appear first. Open the Microsoft record before patching because affected products, FAQs, and update guidance can change after publication.