Deserialization of Untrusted Data in Microsoft SQL Server - CVE-2026-47297
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in SQL Server deserialization functionality when processing untrusted serialized data. A remote attacker can send specially crafted serialized data to execute arbitrary code.
Exploitation requires specific protocol settings or configurations.