PT-2026-32881 · Microsoft · Sql Server 2022+1

David Hayman

·

Published

2026-04-14

·

Updated

2026-05-06

·

CVE-2026-33120

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server 2022 (GDR) versions 16.0.0 through 16.0.1175.0
Description Untrusted pointer dereference allows an authorized attacker to execute arbitrary code over a network by triggering invalid memory access.
Recommendations Update to version 16.0.1175.1.

Fix

RCE

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05353
CVE-2026-33120

Affected Products

Sql Server
Sql Server 2022