Disclosure summary
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Source-reported weakness categories
CWE-89
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2026-Apr
Open original source · Updated Apr 14, 2026
SQL Server Elevation of Privilege Vulnerability
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 6.7
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | Microsoft SQL Server 2025 for x64-based Systems (CU3) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2025 for x64-based Systems (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2022 for x64-based Systems (CU 24) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2017 for x64-based Systems (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2019 for x64-based Systems (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2017 for x64-based Systems (CU 31) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2022 for x64-based Systems (GDR) | (MSRC status code 3) |
| Microsoft update guide | Microsoft SQL Server 2019 for x64-based Systems (CU 32) | (MSRC status code 3) |
Vendor remediation references
- 5083245 · build 17.0.4030.1 · product IDs 21090
- Vendor guidance · product IDs 21090
- 5084814 · build 17.0.1110.1 · product IDs 20748
- Vendor guidance · product IDs 20748
- 5083252 · build 16.0.4250.1 · product IDs 21091
- Vendor guidance · product IDs 21091
- 5084819 · build 14.0.2105.1 · product IDs 11478
- Vendor guidance · product IDs 11478
- 5084817 · build 15.0.2165.1 · product IDs 11821
- Vendor guidance · product IDs 11821
- 5084821 · build 13.0.6485.1 · product IDs 12048
- Vendor guidance · product IDs 12048
- 5084820 · build 13.0.7080.1 · product IDs 12053
- Vendor guidance · product IDs 12053
- 5084818 · build 14.0.3525.1 · product IDs 12145
- Vendor guidance · product IDs 12145
- 5084815 · build 16.0.1175.1 · product IDs 12147
- Vendor guidance · product IDs 12147
- 5084816 · build 15.0.4465.1 · product IDs 16785
- Vendor guidance · product IDs 16785
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2026-04-14T03:00:00-04:00
MODIFIED 2026-04-14T03:00:00-04:00
INGESTED 2026-10-08T12:45:05-04:00