ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday security updates for July 2025 fixed a zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-49719CVE-2025-47981CVE-2025-49695

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-47981
Unauthenticated Heap Buffer Overflow RCE in Windows SPNEGO (CVE-2025-47981)

CVE-2025-47981 is a critical (CVSS 9.8) heap-based buffer overflow (CWE-122) in the Windows SPNEGO Extended Negotiation component, part of Windows' Negotiate authentication stack. An unauthenticated remote attacker can trigger the overflow by sending specially crafted authentication negotiation traffic to a service that processes SPNEGO/Negotiate authentication over the network. Successful exploitation yields remote code execution with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), and press coverage of the July 2025 release describes the bug as potentially wormable. All listed supported Windows 10 and Windows 11 client builds and Windows Server 2008, 2012, 2016 and 2019 are affected, since SPNEGO is a default Windows component. The flaw was fixed in the July 2025 Patch Tuesday; it is not yet in CISA KEV and Microsoft reported no active exploitation, but public proof-of-concept code and detection/mitigation scripts exist, and EPSS estimates a 32.6% probability of exploitation within 30 days (98th percentile).

Do: Apply the July 2025 Microsoft Patch Tuesday security updates (the cumulative updates for the affected Windows 10/11 client branches and Windows Server 2008/2012/2016/2019) on all systems, prioritizing internet-facing servers and hosts that accept Negotiate/SPNEGO authentication such as web and application servers. Until patched, limit untrusted network access to services using Negotiate authentication and use the published third-party detection and mitigation scripts (e.g., the Vicarius scripts referenced in public coverage) to identify and contain vulnerable hosts. No active exploitation has been reported as of the July 2025 release, but public PoCs exist, so patch before widespread scanning or weaponization begins.

9.833% PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2 (all builds in these service branches per the advisory)
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ Windows client and server installations (SPNEGO/Negotiate is a default Windows component present on every in-scope Windows 10/11 and Server build)
CVE-2025-49695
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
8.4<1%
  • microsoft 365 apps
  • microsoft 365 copilot
  • microsoft office
  • +1 more
CVE-2025-49719
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

NVD description · AI analysis pending
7.511%
  • microsoft sql server 2016
  • microsoft sql server 2017
  • microsoft sql server 2019
  • +1 more
Full article320 words · extracted from securityaffairs.com · click to collapse

Microsoft released Patch Tuesday security updates for July 2025, which addressed 130 flaws, including one a Microsoft SQL Server zero-day.

Microsoft Patch Tuesday security updates for July 2025 addressed 130 vulnerabilities in Windows and Windows Components, Office and Office Components, .NET and Visual Studio, Azure, Teams, Hyper-V, Windows BitLocker, Microsoft Edge (Chromium-based), and the Windows Cryptographic Service.

10 vulnerabilities addressed by the company are rated Critical, and the rest is rated Important in severity.

Only one of the flaws, tracked as CVE-2025-49719, is flagged as a publicly disclosed zero-day vulnerability in Microsoft SQL Server. Below are some of the most interesting issues addressed by Microsoft Patch Tuesday for July 2025:

The vulnerability CVE-2025-49719 (CVSS score of 7.5) is an information disclosure flaw in Microsoft SQL Server that allows remote, unauthenticated attackers to access uninitialized memory due to improper input validation. Microsoft recommends updating SQL Server and installing OLE DB Driver 18 or 19 to fix the issue. The flaw was discovered by Vladimir Aleksic from Microsoft.

The vulnerability CVE-2025-47981 (CVSS score of 9.8) is a critical, wormable RCE issue in Windows SPNEGO NEGOEX. It allows remote attackers to execute code via a malicious message, with no user interaction required. The flaw involves a heap-based buffer overflow and runs with elevated privileges. Microsoft expects active exploitation within 30 days and urges rapid patching.

The vulnerability CVE-2025-49695 (CVSS score of 8.8) is a Microsoft Office RCE vulnerability exploitable via the Preview Pane. It’s one of four similar bugs this month—marking the third month in a row with Critical Office flaws. Mac users remain unprotected, as patches for Office LTSC 2021 and 2024 aren’t yet available. Disabling the Preview Pane is recommended until Microsoft resolves these ongoing issues.

The full list of vulnerabilities addressed by Microsoft in July 2025 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179738/security/microsoft-patch-tuesday-security-updates-for-july-2025-fixed-a-zero-day.html