CVE-2019-1068

HIGH(8.8)KEVLikely Exploited

Microsoft SQL Server Remote Code Execution Vulnerability

Description

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

KEV Information

Vendor
Microsoft
Product
SQL Server
Date Added
August 26, 2026
Due Date
August 29, 2026
Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftsql server2014
microsoftsql server 2016>= 13.0.4001.0, < 13.0.4259.0; >= 13.0.4411.0, < 13.0.4604.0; >= 13.0.5026.0, < 13.0.5101.9; >= 13.0.5149.0, < 13.0.5366.0
microsoftsql server 2017>= 14.0.1000.169, < 14.0.2027.2; >= 14.0.3006.16, < 14.0.3192.2

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score52.84%
EPSS Percentile98.9%

Dates

PublishedJuly 15, 2019
Last ModifiedAugust 27, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.