Description
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Severity (CVSS)
| Base score | 6.5 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C |
| Provided by | CNA |
Weaknesses
- CWE-843 — CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft SQL Server 2025 (CU 6) | 17.0.4060.2 to <17.0.4060.2 |
| Microsoft | Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1050.2 to <17.0.1125.2 |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54116 (vendor-advisory patch)
Generated from the official CVE List on 15 Jul 2026 07:06 UTC.