{"cve":{"cve_id":"CVE-2019-1068","is_kev":true,"kev_date_added":"2026-08-26","kev_vendor_project":"Microsoft","kev_product":"SQL Server","kev_vulnerability_name":"Microsoft SQL Server Remote Code Execution Vulnerability","kev_short_description":"Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.","kev_required_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due_date":"2026-08-29","kev_known_ransomware":false,"kev_notes":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2019-1068","kev_cwes":[],"epss_score":0.44665,"epss_percentile":0.98673,"epss_as_of":"2026-08-26","description":"A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.","published_at":"2019-07-15T18:56:20Z","last_modified_at":"2026-08-27T04:16:38.583000Z","cvss_v3_score":8.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":["CWE-20"],"nvd_references":["https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-08-27T17:38:41.369924Z"},"effective_severity":"HIGH","badges":["kev","news"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"L","value_label":"Low"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server","product_name":"Microsoft SQL Server","version_start":"2016 for x64-based Systems Service Pack 2 (CU)","version_start_inclusive":true,"version_end":"2016 for x64-based Systems Service Pack 2 (CU)","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server:2016 for x64-based Systems Service Pack 2 (CU):2016 for x64-based Systems Service Pack 2 (CU)"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server","product_name":"Microsoft SQL Server","version_start":"2014 Service Pack 2 for 32-bit Systems (CU)","version_start_inclusive":true,"version_end":"2014 Service Pack 2 for 32-bit Systems (CU)","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server:2014 Service Pack 2 for 32-bit Systems (CU):2014 Service Pack 2 for 32-bit Systems (CU)"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server","product_name":"Microsoft SQL Server","version_start":"2014 Service Pack 2 for x64-based Systems (CU)","version_start_inclusive":true,"version_end":"2014 Service Pack 2 for x64-based Systems (CU)","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server:2014 Service Pack 2 for x64-based Systems (CU):2014 Service Pack 2 for x64-based Systems (CU)"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server","product_name":"Microsoft SQL Server","version_start":"2016 for x64-based Systems Service Pack 1 (CU)","version_start_inclusive":true,"version_end":"2016 for x64-based Systems Service Pack 1 (CU)","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server:2016 for x64-based Systems Service Pack 1 (CU):2016 for x64-based Systems Service Pack 1 (CU)"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server","product_name":"Microsoft SQL Server","version_start":"2017 for x64-based Systems (CU)","version_start_inclusive":true,"version_end":"2017 for x64-based Systems (CU)","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server:2017 for x64-based Systems (CU):2017 for x64-based Systems (CU)"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2014-service-pack-2-for-32-bit-systems-gdr","product_name":"Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2014-service-pack-2-for-32-bit-systems-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2014-service-pack-2-for-x64-based-systems-gdr","product_name":"Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2014-service-pack-2-for-x64-based-systems-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2014-service-pack-3-for-32-bit-systems-cu","product_name":"Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2014-service-pack-3-for-32-bit-systems-cu:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2014-service-pack-3-for-32-bit-systems-gdr","product_name":"Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2014-service-pack-3-for-32-bit-systems-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2014-service-pack-3-for-x64-based-systems-cu","product_name":"Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2014-service-pack-3-for-x64-based-systems-cu:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2014-service-pack-3-for-x64-based-systems-gdr","product_name":"Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2014-service-pack-3-for-x64-based-systems-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2016-for-x64-based-systems-service-pack-1-gdr","product_name":"Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2016-for-x64-based-systems-service-pack-1-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2016-for-x64-based-systems-service-pack-2-gdr","product_name":"Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2016-for-x64-based-systems-service-pack-2-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"microsoft-sql-server-2017-for-x64-based-systems-gdr","product_name":"Microsoft SQL Server 2017 for x64-based Systems (GDR)","version_start":"unspecified","version_start_inclusive":true,"version_end":"unspecified","version_end_inclusive":true,"cpe23_uri":"cve5:microsoft:microsoft-sql-server-2017-for-x64-based-systems-gdr:unspecified:unspecified"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"sql-server","product_name":"sql_server","version_start":"2014","version_start_inclusive":true,"version_end":"2014","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:sql_server:2014:sp2:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"sql-server","product_name":"sql_server","version_start":"2014","version_start_inclusive":true,"version_end":"2014","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:sql_server:2014:sp3:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"sql-server-2016","product_name":"sql_server_2016","version_start":"13.0.4001.0","version_start_inclusive":true,"version_end":"13.0.4259.0","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"microsoft","product_slug":"sql-server-2017","product_name":"sql_server_2017","version_start":"14.0.1000.169","version_start_inclusive":true,"version_end":"14.0.2027.2","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:*:*"}],"exploit_refs":[],"news":[{"id":1458,"source":"The Hacker News","url":"https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html","title":"CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.\n\nThe vulnerabilities are listed below -\n\n\n  CVE-2019-1068 - A remote code execution vulnerability in&nbsp;","thumbnail_url":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsOm0ydTRNpwfiKMNN7TGZyoellV9LHrcra7ES8hU8PvT6haNsS-QQ5IlystrzP1eq5jiIRfyykIZyB5JKrya5K4ryBRp9gKAmsoVW7OMis-YT4T6jnpbN11M8mUnPn-2yY-caG31-iXmDAhJ9CTbRg8r1UPWWqCob_S8St7McsKCM-4I36jD_xqE8D3BS/s1600/cisa-flaws.jpg","author":"info@thehackernews.com (The Hacker News)","published_at":"2026-08-27T07:05:28Z","fetched_at":"2026-08-27T07:52:11.739917Z","trending_score":1.1274557616826026,"cve_ids":["CVE-2019-1068"]}],"references":[{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068","source_type":"VENDOR_ADVISORY","tags":["advisory"]}],"timeline":[{"type":"published","at":"2019-07-15T18:56:20Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2026-08-26T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-08-26T16:37:20.267850Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-08-26T16:37:20.267850Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-08-26T16:37:20.267850Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-08-26T16:37:20.267850Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-08-26T16:37:20.267850Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-08-26T16:37:20.267850Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-08-26T18:40:11.368954Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"first_article","at":"2026-08-27T07:05:28Z","label":"First news coverage","source":"The Hacker News"}]}