CVE-2026-33120 is an untrusted pointer dereference vulnerability in SQL Server that permits authorized attackers to execute arbitrary code remotely over a network. This vulnerability affects SQL Server systems and requires valid user credentials to exploit, limiting the attack surface to authenticated users with network access. The vulnerability carries a CVSS severity rating of 8.8 (HIGH) with a network attack vector and low attack complexity, indicating that exploitation can be executed easily once authentication is obtained. The impact is severe across all three security dimensions: confidentiality, integrity, and availability are all rated as high, meaning successful exploitation could lead to complete system compromise. Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed on the KEV catalog and is marked as inactive on threat intelligence tracking lists. The EPSS score of 0.0007 suggests minimal real-world exploitation probability to date, though organizations should still prioritize patching given the high CVSS severity rating and complete impact potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.6300.2, < 13.0.6485.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 13.0.7000.253, < 13.0.7080.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 14.0.1000.169, < 14.0.2105.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 14.0.3006.16, < 14.0.3525.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 15.0.2000.5, < 15.0.2165.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.