CVE-2018-8273
9.8
CRITICAL · CVSS 3.1 · EPSS 29.2% (pctl 98)
Patch early
EPSS 29.2% — above the 10% action threshold.
Description
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 29.21% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-08-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | sql server |
References
- http://www.securityfocus.com/bid/104967
- http://www.securitytracker.com/id/1041467
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8273
- http://www.securityfocus.com/bid/104967
- http://www.securitytracker.com/id/1041467
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8273
→ the Explorer · watch your stack · NVD