boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2019-1068

Microsoft Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR) — A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'M…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .5700   99.0   YES
AFFECTED
  Product                                                               Versions                                       Fixed
  Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)     unspecified –                                  —
  Microsoft SQL Server                                                  2014 Service Pack 2 for 32-bit Systems (CU) –  —
  Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)  unspecified –                                  —
  Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)  unspecified –                                  —
  Microsoft SQL Server 2017 for x64-based Systems (GDR)                 unspecified –                                  —
  Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)  unspecified –                                  —
  Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)  unspecified –                                  —
  Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)   unspecified –                                  —
  Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)     unspecified –                                  —
  Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)      unspecified –                                  —
TIMELINE
  Nov 26  Reserved by microsoft
  Jul 15  Published (CNA: microsoft)
  Aug 26  ADDED TO KEV — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). Remediation due August 29, 2026.
  Aug 30  DUE DATE PASSED — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). CISA remediation deadline was August 29, 2026; still in catalog.
CWE-20 · CNA: microsoft · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due August 29, 2026

Description

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
November 26, 2018ReservedReserved by microsoft
July 15, 2019PublishedPublished (CNA: microsoft)
August 26, 2026KEV ADDEDADDED TO KEV — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). Remediation due August 29, 2026.
August 30, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). CISA remediation deadline was August 29, 2026; still in catalog.

Affected

Affected products and packages — 10 rows
VendorProduct / PackageEcosystemVersion introducedFixed
MicrosoftMicrosoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)—unspecified—
MicrosoftMicrosoft SQL Server—2014 Service Pack 2 for 32-bit Systems (CU)—
MicrosoftMicrosoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)—unspecified—
MicrosoftMicrosoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)—unspecified—
MicrosoftMicrosoft SQL Server 2017 for x64-based Systems (GDR)—unspecified—
MicrosoftMicrosoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)—unspecified—
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)—unspecified—
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)—unspecified—
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)—unspecified—
MicrosoftMicrosoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)—unspecified—

Weaknesses

CWE-20

References (2)

Related

Authoritative record: CVE-2019-1068 at cve.org

Vendors: microsoft

Weaknesses: CWE-20

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2019-1068 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.