Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C 15.0.0.0 (custom) before 15.0.4435.7
affected
15.0.0 (custom) before 15.0.2135.5
affected
16.0.0.0 (custom) before 16.0.4200.1
affected
16.0.0 (custom) before 16.0.1140.6
affected
Description
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
Problem types
CWE-908: Use of Uninitialized Resource
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49718 (Microsoft SQL Server Information Disclosure Vulnerability)