Views
9

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5084818 updates SQL Server 2017 CU31 to 14.0.3525.1 and addresses elevation-of-privilege vulnerabilities, including CVE-2026-32167 and CVE-2026-32176. It also fixes linked-server and SQL Agent security issues.

Update Details

Security

  • Fixes CVE-2026-32167, an elevation-of-privilege vulnerability in SQL Server linked servers that could let a low-privileged user gain sysadmin permissions.
  • Fixes CVE-2026-32176, a SQL injection issue in SQL Server that could allow an authorized attacker to elevate privileges over the network.

Bug Fixes

  • Updates SQL Server 2017 components to build 14.0.3525.1.
  • Addresses a linked-server elevation-of-privilege issue in the SQL Server Engine.
  • Fixes a SQL Agent privilege-escalation issue caused by improper neutralization of special elements in SQL commands.

Known Issues

  • Linked server queries that use MSDASQL with a provider string may fail with error 7416: 'Access to the remote server is denied because no login-mapping exists.'
  • A stricter Database Engine connection validation check can reject some linked server configurations that use the MSDASQL provider.

Hints

  • Prerequisite: SQL Server 2017 or any SQL Server 2017 CU release through SQL Server 2017 CU31 GDR must already be installed.
  • If you install a language pack after installing this update, you must reinstall the update.
  • The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
  • Installing this security update is optional for computers that do not host Microsoft SQL Server Reporting Services.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2017

Version: 14.0.3525.1

Vendor release date: Apr 14, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026