ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited

criticalVulnerability exploited in the wildimportance 60CVE-2025-49719CVE-2025-47981

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-47981
Unauthenticated Heap Buffer Overflow RCE in Windows SPNEGO (CVE-2025-47981)

CVE-2025-47981 is a critical (CVSS 9.8) heap-based buffer overflow (CWE-122) in the Windows SPNEGO Extended Negotiation component, part of Windows' Negotiate authentication stack. An unauthenticated remote attacker can trigger the overflow by sending specially crafted authentication negotiation traffic to a service that processes SPNEGO/Negotiate authentication over the network. Successful exploitation yields remote code execution with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), and press coverage of the July 2025 release describes the bug as potentially wormable. All listed supported Windows 10 and Windows 11 client builds and Windows Server 2008, 2012, 2016 and 2019 are affected, since SPNEGO is a default Windows component. The flaw was fixed in the July 2025 Patch Tuesday; it is not yet in CISA KEV and Microsoft reported no active exploitation, but public proof-of-concept code and detection/mitigation scripts exist, and EPSS estimates a 32.6% probability of exploitation within 30 days (98th percentile).

Do: Apply the July 2025 Microsoft Patch Tuesday security updates (the cumulative updates for the affected Windows 10/11 client branches and Windows Server 2008/2012/2016/2019) on all systems, prioritizing internet-facing servers and hosts that accept Negotiate/SPNEGO authentication such as web and application servers. Until patched, limit untrusted network access to services using Negotiate authentication and use the published third-party detection and mitigation scripts (e.g., the Vicarius scripts referenced in public coverage) to identify and contain vulnerable hosts. No active exploitation has been reported as of the July 2025 release, but public PoCs exist, so patch before widespread scanning or weaponization begins.

9.833% PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2 (all builds in these service branches per the advisory)
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ Windows client and server installations (SPNEGO/Negotiate is a default Windows component present on every in-scope Windows 10/11 and Server build)
CVE-2025-49719
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

NVD description · AI analysis pending
7.511%
  • microsoft sql server 2016
  • microsoft sql server 2017
  • microsoft sql server 2019
  • +1 more
Full article589 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Researchers are especially concerned about a high-severity defect in SQL Server and a critical vulnerability in SPNEGO, a foundational protocol.

Listen to this article

0:00

Learn more.

Microsoft
(Jeenah Moon/Getty Images)

Microsoft addressed 130 vulnerabilities across its products and underlying Windows systems, but none have been actively exploited in the wild, the company said in its latest security update Tuesday.

A proof-of-concept exploit for a high-severity defect in SQL Server — CVE-2025-49719 — has been shared publicly, researchers said. The information disclosure vulnerability, which has a CVSS score of 7.5, was publicly disclosed before it was patched, but Microsoft said exploitation is less likely.

“This vulnerability likely stems from improper input validation in SQL Server’s memory management, allowing access to uninitialized memory. As a result, attackers could retrieve remnants of sensitive data, such as credentials or connection strings,” Mike Walters, president and co-founder of Action1, said in an email.

Walters said the defect is especially concerning because authentication isn’t required, databases hold vast amounts of sensitive data and affected versions span releases from 2016 through 2022. 

“Although rated as ‘exploitation less likely,’ the public disclosure suggests technical details may already be circulating, which could lead to increased exploitation over time,” he added. “This vulnerability can be exploited in advanced attack scenarios.”

The most critical vulnerability in this month’s security update — CVE-2025-47981 — is a remote code execution vulnerability in Windows SPNEGO Extended Negotiation with a CVSS score of 9.8. The foundational protocol negotiates authentication on critical services.

“This vulnerability enables unauthenticated, pre-authentication remote code execution with no user interaction and low attack complexity, making it a high-value target for adversaries seeking lateral movement or initial access in enterprise networks,” Ben McCarthy, lead cyber security engineer at Immersive, said in an email.

Ben Harris, CEO at watchTowr, encouraged defenders to patch CVE-2025-47981 quickly and hunt down exposed systems. 

“We shouldn’t fool ourselves,” Harris said. “If the private industry has noticed this vulnerability, it is certainly already on the radar of every attacker with an ounce of malice.”

Microsoft’s batch of CVE disclosures includes 16 vulnerabilities that affect Microsoft Office and standalone Office products, including four defects the company described as more likely to be exploited.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-july-2025/