Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Microsoft · AUTOMATIC DISCOVERY

SQL Server 2017

SQL Server is tracked by BlackTree as a database platform or data-management product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

SQL Server is tracked by BlackTree as a database platform or data-management product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Persistent data storage
  • Application data querying and management
  • Backup, security and operational administration

Typical use

Used as an application data store, analytical platform or managed data service.

Deployment

Operated on servers, virtual machines, containers or a vendor-managed cloud service.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductSQL Server
Release2017
End of Fixed Lifecycle Policy12 October 2027
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2019-1068Added 26 Aug 2026

Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

Microsoft · SQL ServerRansomware use: Unknown

CISA entry
CVE-2020-0618Added 18 Sep 2024

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

Microsoft · SQL ServerRansomware use: Known

CISA entry

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYReady

Microsoft lifecycle discovery

{"display_products": ["SQL Server"], "end": "2027-10-13T06:59:59.999Z", "last_modified": "2022-10-10T00:00:00Z", "locale": "en-us", "products": ["sql-server"], "start": "2017-09-29T08:00:00Z", "summary": "SQL Server 2017 follows the Fixed Lifecycle Policy.", "title": "SQL Server 2017", "url": "/lifecycle/products/sql-server-2017"}

Official vendor lifecycle or product-change property. Extracted records require human review.

First collected 25 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source