CVE-2019-1068 is a remote code execution vulnerability affecting Microsoft SQL Server. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of the SQL Server Database Engine service account. The vulnerability is tracked by CISA and is subject to BOD 26-04, which prioritizes security updates based on risk. Microsoft has published an official advisory through the Microsoft Security Response Center. CISA also references forensic triage requirements under BOD 26-04 implementation guidance. The vulnerability is catalogued in the National Vulnerability Database (NVD). Organizations running affected versions of Microsoft SQL Server are advised to apply the relevant security patches promptly. The current risk rating is High (H), indicating significant potential impact if exploited.