EUVD Vulnerability Catalog
Actively Exploited (KEV)
EUVD-2019-9650
Severity: HIGH
Base Score: 8.8
CVSS Version: 3.1
Vulnerability Description
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): Low
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
Microsoft
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
microsoft
EPSS Probability
44.67
Known Aliases
CVE-2019-1068
GHSA-62pw-5pr4-ghr5
Published On
2019-07-15
Last Updated
2026-08-26
Exploited Since
2026-08-26