Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Microsoft Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR) — A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'M…
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .5700 99.0 YES
AFFECTED
Product Versions Fixed
Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR) unspecified – —
Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (CU) – —
Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR) unspecified – —
Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR) unspecified – —
Microsoft SQL Server 2017 for x64-based Systems (GDR) unspecified – —
Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR) unspecified – —
Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR) unspecified – —
Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU) unspecified – —
Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR) unspecified – —
Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU) unspecified – —
TIMELINE
Nov 26 Reserved by microsoft
Jul 15 Published (CNA: microsoft)
Aug 26 ADDED TO KEV — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). Remediation due August 29, 2026.
Aug 30 DUE DATE PASSED — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). CISA remediation deadline was August 29, 2026; still in catalog.
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2019-1068 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.