Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Microsoft SQL Server 2017 (GDR).
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-47295HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-89Jul 14, 2026 | CVSS8.8v3.1 | EPSS0.922% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55002HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityExternal control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally. CWE-73Jul 14, 2026 | CVSS8.8v3.1 | EPSS0.618% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-54118HIGH | Microsoft SQL Server Remote Code Execution VulnerabilityDeserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. CWE-502Jul 14, 2026 | CVSS8.8v3.1 | EPSS1.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47296HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. CWE-89Jul 14, 2026 | CVSS7.5v3.1 | EPSS0.497% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40370HIGH | SQL Server Remote Code Execution VulnerabilityExternal control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | CVSS8.8v3.1 | EPSS0.555% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32176MEDIUM | SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. CWE-89Apr 14, 2026 | CVSS6.7v3.1 | EPSS0.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32167MEDIUM | SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. CWE-89Apr 14, 2026 | CVSS6.7v3.1 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-26115HIGH | SQL Server Elevation of Privilege VulnerabilityImproper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-1287Mar 10, 2026 | CVSS8.8v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21262HIGH | SQL Server Elevation of Privilege VulnerabilityImproper access control in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-284Mar 10, 2026 | CVSS8.8v3.1 | EPSS2.04% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59499HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-89Nov 11, 2025 | CVSS8.8v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-55227HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-77Sep 9, 2025 | CVSS8.8v3.1 | EPSS1.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47997MEDIUM | Microsoft SQL Server Information Disclosure VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | CVSS6.5v3.1 | EPSS0.82% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49759HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-89Aug 12, 2025 | CVSS8.8v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24999HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper access control in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-284Aug 12, 2025 | CVSS8.8v3.1 | EPSS1.63% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53727HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-89Aug 12, 2025 | CVSS8.8v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49758HIGH | Microsoft SQL Server Elevation of Privilege VulnerabilityImproper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. CWE-269Aug 12, 2025 | CVSS8.8v3.1 | EPSS0.927% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49719HIGH | Microsoft SQL Server Information Disclosure VulnerabilityImproper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. CWE-20Jul 8, 2025 | CVSS7.5v3.1 | EPSS10.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49021HIGH | Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft SQL Server Remote Code Execution Vulnerability CWE-416Nov 12, 2024 | CVSS7.8v3.1 | EPSS0.736% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49018HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-197Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49017HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-122Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49016HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-416Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49015HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-122Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49014HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-415Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49013HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-122Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49012HIGH | SQL Server Native Client Remote Code Execution VulnerabilitySQL Server Native Client Remote Code Execution Vulnerability CWE-122Nov 12, 2024 | CVSS8.8v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |