CVE Details

CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
Published: 2026-08-26 CVSS: 8.8 HIGH Product: Microsoft SQL Server Due Date: 2026-08-29

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

No GitHub PoC data.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 8.8
  • Severity: HIGH
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
containers > cna > affected > 0 > product Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)
containers > cna > affected > 0 > vendor Microsoft
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version unspecified
containers > cna > affected > 1 > product Microsoft SQL Server
containers > cna > affected > 1 > vendor Microsoft
containers > cna > affected > 1 > versions > 0 > status affected
containers > cna > affected > 1 > versions > 0 > version 2014 Service Pack 2 for 32-bit Systems (CU)
containers > cna > affected > 1 > versions > 1 > status affected
containers > cna > affected > 1 > versions > 1 > version 2014 Service Pack 2 for x64-based Systems (CU)
containers > cna > affected > 1 > versions > 2 > status affected
containers > cna > affected > 1 > versions > 2 > version 2016 for x64-based Systems Service Pack 1 (CU)
containers > cna > affected > 1 > versions > 3 > status affected
containers > cna > affected > 1 > versions > 3 > version 2017 for x64-based Systems (CU)
containers > cna > affected > 1 > versions > 4 > status affected
containers > cna > affected > 1 > versions > 4 > version 2016 for x64-based Systems Service Pack 2 (CU)
containers > cna > affected > 2 > product Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)
containers > cna > affected > 2 > vendor Microsoft
containers > cna > affected > 2 > versions > 0 > status affected
containers > cna > affected > 2 > versions > 0 > version unspecified
containers > cna > affected > 3 > product Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)
containers > cna > affected > 3 > vendor Microsoft
containers > cna > affected > 3 > versions > 0 > status affected
containers > cna > affected > 3 > versions > 0 > version unspecified
containers > cna > affected > 4 > product Microsoft SQL Server 2017 for x64-based Systems (GDR)
containers > cna > affected > 4 > vendor Microsoft
containers > cna > affected > 4 > versions > 0 > status affected
containers > cna > affected > 4 > versions > 0 > version unspecified
containers > cna > affected > 5 > product Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)
containers > cna > affected > 5 > vendor Microsoft
containers > cna > affected > 5 > versions > 0 > status affected
containers > cna > affected > 5 > versions > 0 > version unspecified
containers > cna > affected > 6 > product Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)
containers > cna > affected > 6 > vendor Microsoft
containers > cna > affected > 6 > versions > 0 > status affected
containers > cna > affected > 6 > versions > 0 > version unspecified
containers > cna > affected > 7 > product Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)
containers > cna > affected > 7 > vendor Microsoft
containers > cna > affected > 7 > versions > 0 > status affected
containers > cna > affected > 7 > versions > 0 > version unspecified
containers > cna > affected > 8 > product Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
containers > cna > affected > 8 > vendor Microsoft
containers > cna > affected > 8 > versions > 0 > status affected
containers > cna > affected > 8 > versions > 0 > version unspecified
containers > cna > affected > 9 > product Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)
containers > cna > affected > 9 > vendor Microsoft
containers > cna > affected > 9 > versions > 0 > status affected
containers > cna > affected > 9 > versions > 0 > version unspecified
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
containers > cna > problemTypes > 0 > descriptions > 0 > description Remote Code Execution
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type text
containers > cna > providerMetadata > dateUpdated 2019-07-15T18:56:20.000Z
containers > cna > providerMetadata > orgId f38d906d-7342-40ea-92c1-6c4a2c6478c8
containers > cna > providerMetadata > shortName microsoft
containers > cna > references > 0 > tags > 0 x_refsource_MISC
containers > cna > references > 0 > url https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
containers > cna > x_legacyV4Record > CVE_data_meta > ASSIGNER [email protected]
containers > cna > x_legacyV4Record > CVE_data_meta > ID CVE-2019-1068
containers > cna > x_legacyV4Record > CVE_data_meta > STATE PUBLIC
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > product_name Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 1 > product_name Microsoft SQL Server
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 1 > version > version_data > 0 > version_value 2014 Service Pack 2 for 32-bit Systems (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 1 > version > version_data > 1 > version_value 2014 Service Pack 2 for x64-based Systems (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 1 > version > version_data > 2 > version_value 2016 for x64-based Systems Service Pack 1 (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 1 > version > version_data > 3 > version_value 2017 for x64-based Systems (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 1 > version > version_data > 4 > version_value 2016 for x64-based Systems Service Pack 2 (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 2 > product_name Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 2 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 3 > product_name Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 3 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 4 > product_name Microsoft SQL Server 2017 for x64-based Systems (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 4 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 5 > product_name Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 5 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 6 > product_name Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 6 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 7 > product_name Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 7 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 8 > product_name Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 8 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 9 > product_name Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 9 > version > version_data > 0 > version_value
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > vendor_name Microsoft
containers > cna > x_legacyV4Record > data_format MITRE
containers > cna > x_legacyV4Record > data_type CVE
containers > cna > x_legacyV4Record > data_version 4.0
containers > cna > x_legacyV4Record > description > description_data > 0 > lang eng
containers > cna > x_legacyV4Record > description > description_data > 0 > value A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > lang eng
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > value Remote Code Execution
containers > cna > x_legacyV4Record > references > reference_data > 0 > name https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
containers > cna > x_legacyV4Record > references > reference_data > 0 > refsource MISC
containers > cna > x_legacyV4Record > references > reference_data > 0 > url https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
containers > adp > 0 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 0 > providerMetadata > shortName CVE
containers > adp > 0 > providerMetadata > dateUpdated 2024-08-04T18:06:31.612Z
containers > adp > 0 > title CVE Program Container
containers > adp > 0 > references > 0 > tags > 0 x_refsource_MISC
containers > adp > 0 > references > 0 > tags > 1 x_transferred
containers > adp > 0 > references > 0 > url https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
containers > adp > 1 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 1 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseScore 8.8
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 1 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
containers > adp > 1 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 1 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 1 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 1 > metrics > 0 > cvssV3_1 > privilegesRequired LOW
containers > adp > 1 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 1 > metrics > 1 > other > type ssvc
containers > adp > 1 > metrics > 1 > other > content > id CVE-2019-1068
containers > adp > 1 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 1 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 1 > metrics > 1 > other > content > options > 1 > Automatable no
containers > adp > 1 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 1 > metrics > 1 > other > content > version 2.0.3
containers > adp > 1 > metrics > 1 > other > content > timestamp 2026-08-26T17:44:35.078686Z
containers > adp > 1 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1068
containers > adp > 1 > references > 0 > tags > 0 government-resource
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > cweId CWE-20
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > description CWE-20 Improper Input Validation
containers > adp > 1 > title CISA ADP Vulnrichment
containers > adp > 1 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 1 > providerMetadata > shortName CISA-ADP
containers > adp > 1 > providerMetadata > dateUpdated 2026-08-26T17:44:59.008Z
cveMetadata > assignerOrgId f38d906d-7342-40ea-92c1-6c4a2c6478c8
cveMetadata > assignerShortName microsoft
cveMetadata > cveId CVE-2019-1068
cveMetadata > datePublished 2019-07-15T18:56:20.000Z
cveMetadata > dateReserved 2018-11-26T00:00:00.000Z
cveMetadata > dateUpdated 2026-08-26T17:44:59.008Z
cveMetadata > state PUBLISHED
dataType CVE_RECORD
dataVersion 5.2