sql_server_2022_for_x64-based_systems_cu_24 vulnerabilities
CVEs whose affected-version data names the sql_server_2022_for_x64-based_systems_cu_24 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-32167Medium· 6.7SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
▾ SunlitMicrosoft · Microsoft SQL Server 2016 Service Pack 3 (GDR)EPSS 0.32%via CVEORG
CVE-2026-32176Medium· 6.7SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
▾ SunlitMicrosoft · Microsoft SQL Server 2016 Service Pack 3 (GDR)EPSS 0.32%via CVEORG