Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026041709041414 | Publication Time | 2026/04/17 09:53 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/04/17 09:53 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Microsoft SQL Server (CVE-2026-33120) |
|||
| [Content] Forwarded from TWCERTCC-200-202604-00000020 Microsoft has issued a critical security vulnerability advisory for its SQL Server product (CVE-2026-33120, CVSS: 8.8). This is an Untrusted Pointer Dereference vulnerability that allows an authorized attacker to execute code over a network. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform]
Microsoft SQL Server 2022 (GDR) versions 16.0.0 through 16.0.1175.1 |
|||
| [Recommended Actions] Please apply the remediation in accordance with the solution provided on the official website. https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33120 |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10851-e7d71-1.html |
|||