THREAT OPS › CVEs › CVE-2019-1068
CVE-2019-1068 — Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Vulnerability details
- Affected productsSQL Server
- KEV remediation due2026-08-29
Related reporting
- August 2026 CVE Landscaperecordedfuture
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugsthehackernews
- CISA Adds Six Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2019-1068 — Microsoft SQL Server: Microsoft SQL Server Remote Code Execution Vulnerabilitycisa_kev
- [NVD] CVE-2019-1068 (HIGH 8.8) — A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.nvd