Severity
5.3MEDIUM
EPSS
0.1%
top 69.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5microsoft/microsoft_sql_server_2017_(gdr)14.0.014.0.2085.1
CVEListV5microsoft/microsoft_sql_server_2019_(gdr)15.0.015.0.2145.1
CVEListV5microsoft/microsoft_sql_server_2022_(gdr)16.0.016.0.1150.1
CVEListV5microsoft/microsoft_sql_server_2017_(cu_31)14.0.014.0.3505.1
CVEListV5microsoft/microsoft_sql_server_2019_(cu_32)15.0.0.015.0.4445.1

🔴Vulnerability Details

2
CVEList
Microsoft SQL Server Information Disclosure Vulnerability2025-09-09
GHSA
GHSA-8r8h-58x3-gfr7: Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose in2025-09-09

📋Vendor Advisories

1
Microsoft
Microsoft SQL Server Information Disclosure Vulnerability2025-09-09
CVE-2025-47997 (MEDIUM CVSS 5.3) | Concurrent execution using shared r | cvebase.io