Vulnerabilities Fixed in Microsoft SQL Server (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Three vulnerabilities patched in Microsoft SQL Server
- CVE-2026-32167 and CVE-2026-32176: local privilege escalation
- CVE-2026-33120: remote code execution (CVSS 8.8)
"Microsoft has addressed vulnerabilities in SQL Server. The flaws allow an attacker to escalate privileges locally or execute remote code due to insufficient input neutralization and unsafe dereferencing of untrusted pointers. The vulnerabilities are tracked as CVE-2026-32167 (CVSS 6.7), CVE-2026-33120 (CVSS 8.8), and CVE-2026-32176 (CVSS 6.7)."
no comments yet.