CVE-2026-78442HighCVSS 8.8

Windows OLE DB Remote Code Execution Vulnerability

Published
September 11, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

🎯 Affected products4

  • Microsoft SQL Server 2017 for x64-based Systems (CU 31)
  • Microsoft SQL Server 2017 for x64-based Systems (GDR)
  • Microsoft SQL Server 2019 for x64-based Systems (CU 32)
  • Microsoft SQL Server 2019 for x64-based Systems (GDR)

✅ Remediation

KB5122775 (Security Update) — fixed build 14.0.2130.4 KB5122773 (Security Update) — fixed build 15.0.2190.7 KB5122774 (Security Update) — fixed build 14.0.3550.4 KB5122772 (Security Update) — fixed build 15.0.4490.9

🔗 References (9)