CVE-2026-72933
8.8Microsoft · Windows
A heap-based buffer overflow in the Microsoft WDAC OLE DB provider for SQL allows an unauthenticated remote attacker to execute arbitrary code.
Executive summary
A heap-based buffer overflow vulnerability in the Microsoft WDAC OLE DB provider for SQL exposes multiple versions of Windows to potential remote code execution.
Vulnerability
This is a heap-based buffer overflow (CWE-122) occurring within the Microsoft WDAC OLE DB provider for SQL. The vulnerability allows an unauthenticated, remote attacker to trigger memory corruption and achieve code execution on the target system.
Business impact
The ability for an unauthenticated attacker to execute code remotely poses a severe threat to system integrity and confidentiality. With a CVSS score of 8.8, this vulnerability is classified as High, reflecting the potential for full system compromise, unauthorized data access, and lateral movement within the network. Failure to remediate could lead to significant operational disruption and data loss.
Remediation
Immediate Action: Update all affected Windows installations to the versions listed in the fixed_versions field provided by Microsoft.
Proactive Monitoring: Monitor network traffic for anomalous OLE DB provider requests and review system event logs for unexpected process crashes or unauthorized execution attempts.
Compensating Controls: Ensure that Windows Defender or equivalent endpoint protection is active, and restrict network access to SQL-related services to trusted internal segments to minimize the attack surface.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the potential for remote code execution, this vulnerability represents a significant security risk to enterprise environments. Administrators should prioritize the deployment of the vendor-supplied security updates to all vulnerable Windows endpoints to prevent exploitation. Consistent with standard security hygiene, verify the integrity of the patch deployment across all affected versions to ensure full coverage.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section