Knox CVE Database
/
CVE-2019-1068
High
8.8

CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

Added to the CISA KEV catalog:
August 26, 2026

Overview

Microsoft SQL Server contains an improper input validation flaw in its Database Engine's handling of internal functions. An authenticated attacker with low-privilege network access can submit a specially crafted SQL query that triggers the flaw, gaining code execution under the SQL Server service account. Affected versions span SQL Server 2014 (Service Pack 2 and SP3), 2016 (SP1 and SP2), and 2017 across both GDR and Cumulative Update servicing tracks.

Vulnerability details

Affected vendor
Microsoft
Affected product
SQL Server
Weakness type (CWE)
CWE-20

The flaw is classified as improper input validation (CWE-20): the Database Engine fails to correctly validate attacker-controlled input when processing certain internal functions during query execution. Rather than rejecting or safely handling the malformed construct, the engine processes it in a way that allows attacker-influenced code to run. This class of weakness is particularly dangerous in a database engine because query parsing and function evaluation occur deep within a trusted execution context, where the engine operates with elevated system privileges by design.


An attacker who holds any valid SQL Server credential, including a low-privilege account, can send a specially crafted query to a network-reachable SQL Server instance. No user interaction or elevated database role is required beyond that initial authentication. A successful exploit executes arbitrary code in the context of the SQL Server Database Engine service account, which typically carries significant operating-system privileges. The attacker gains a foothold on the host running SQL Server, from which lateral movement or further privilege escalation becomes possible.

Severity and impact

8.8
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor SQL Server error logs and Windows Event Logs for unexpected process spawning or child processes originating from the SQL Server service (sqlservr.exe), which would not appear during normal query execution.
  • Audit SQL Server login events for accounts authenticating from unexpected source addresses or at unusual times, then immediately executing queries against system or internal functions, with no corresponding application-tier session.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 29, 2026

Additional hardening

  • Apply the July 2019 security updates from Microsoft: for SQL Server 2017, update to 14.0.2027.2 (GDR) or 14.0.3192.2 (CU); for SQL Server 2016 SP1, update to 13.0.4259.0 (GDR) or 13.0.4604.0 (CU). See References for the full update table covering SQL Server 2014 and 2016 SP2 boundaries.
  • Restrict network access to SQL Server ports (default TCP 1433) using host-based firewalls and network segmentation, limiting connections to known application servers and administrative hosts only.
  • Audit and reduce the number of accounts with SQL Server login rights; remove or disable any accounts not required for application operation to shrink the authenticated attacker surface.
  • Run the SQL Server service under a least-privilege dedicated service account rather than a high-privilege or SYSTEM account, limiting the impact of successful code execution.

Key dates

Published (NVD)
July 15, 2019
Added to CISA KEV
August 26, 2026
Remediation deadline
August 29, 2026
Last updated
August 27, 2026

References

Frequently asked questions

Does CVE-2019-1068 affect my FedRAMP authorization?

If Microsoft SQL Server runs inside your authorization boundary, CVE-2019-1068 creates a direct FedRAMP compliance obligation. CISA lists this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 29, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it before that date or formally document a mitigation, or your sponsoring agency will raise it during review.

How does Knox help me handle CVE-2019-1068?

Knox does not patch Microsoft SQL Server on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2019-1068 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2019-1068 surfaces, exposure is identified through continuous monitoring rather than waiting for an assessor to flag it at scheduled review time. That gap between disclosure and discovery shrinks considerably.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2019-1068 isn't remediated by August 29, 2026?

Missing the August 29, 2026 deadline converts CVE-2019-1068 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing intact and preserves the agency relationship.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting