Microsoft Patch Tuesday addresses 130 vulnerabilities, none actively exploited
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-47981 | Unauthenticated Heap Buffer Overflow RCE in Windows SPNEGO (CVE-2025-47981) CVE-2025-47981 is a critical (CVSS 9.8) heap-based buffer overflow (CWE-122) in the Windows SPNEGO Extended Negotiation component, part of Windows' Negotiate authentication stack. An unauthenticated remote attacker can trigger the overflow by sending specially crafted authentication negotiation traffic to a service that processes SPNEGO/Negotiate authentication over the network. Successful exploitation yields remote code execution with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), and press coverage of the July 2025 release describes the bug as potentially wormable. All listed supported Windows 10 and Windows 11 client builds and Windows Server 2008, 2012, 2016 and 2019 are affected, since SPNEGO is a default Windows component. The flaw was fixed in the July 2025 Patch Tuesday; it is not yet in CISA KEV and Microsoft reported no active exploitation, but public proof-of-concept code and detection/mitigation scripts exist, and EPSS estimates a 32.6% probability of exploitation within 30 days (98th percentile). Do: Apply the July 2025 Microsoft Patch Tuesday security updates (the cumulative updates for the affected Windows 10/11 client branches and Windows Server 2008/2012/2016/2019) on all systems, prioritizing internet-facing servers and hosts that accept Negotiate/SPNEGO authentication such as web and application servers. Until patched, limit untrusted network access to services using Negotiate authentication and use the published third-party detection and mitigation scripts (e.g., the Vicarius scripts referenced in public coverage) to identify and contain vulnerable hosts. No active exploitation has been reported as of the July 2025 release, but public PoCs exist, so patch before widespread scanning or weaponization begins. | 9.8 | 33% | PoC ×3 |
| mass≈1 billion+ Windows client and server installations (SPNEGO/Negotiate is a default Windows component present on every in-scope Windows 10/11 and Server build) | |
| CVE-2025-49719 | Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. NVD description · AI analysis pending | 7.5 | 11% |
| — |
Full article589 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers are especially concerned about a high-severity defect in SQL Server and a critical vulnerability in SPNEGO, a foundational protocol.
Listen to this article
0:00
Learn more.
Microsoft addressed 130 vulnerabilities across its products and underlying Windows systems, but none have been actively exploited in the wild, the company said in its latest security update Tuesday.
A proof-of-concept exploit for a high-severity defect in SQL Server — CVE-2025-49719 — has been shared publicly, researchers said. The information disclosure vulnerability, which has a CVSS score of 7.5, was publicly disclosed before it was patched, but Microsoft said exploitation is less likely.
“This vulnerability likely stems from improper input validation in SQL Server’s memory management, allowing access to uninitialized memory. As a result, attackers could retrieve remnants of sensitive data, such as credentials or connection strings,” Mike Walters, president and co-founder of Action1, said in an email.
Walters said the defect is especially concerning because authentication isn’t required, databases hold vast amounts of sensitive data and affected versions span releases from 2016 through 2022.
“Although rated as ‘exploitation less likely,’ the public disclosure suggests technical details may already be circulating, which could lead to increased exploitation over time,” he added. “This vulnerability can be exploited in advanced attack scenarios.”
The most critical vulnerability in this month’s security update — CVE-2025-47981 — is a remote code execution vulnerability in Windows SPNEGO Extended Negotiation with a CVSS score of 9.8. The foundational protocol negotiates authentication on critical services.
“This vulnerability enables unauthenticated, pre-authentication remote code execution with no user interaction and low attack complexity, making it a high-value target for adversaries seeking lateral movement or initial access in enterprise networks,” Ben McCarthy, lead cyber security engineer at Immersive, said in an email.
Ben Harris, CEO at watchTowr, encouraged defenders to patch CVE-2025-47981 quickly and hunt down exposed systems.
“We shouldn’t fool ourselves,” Harris said. “If the private industry has noticed this vulnerability, it is certainly already on the radar of every attacker with an ounce of malice.”
Microsoft’s batch of CVE disclosures includes 16 vulnerabilities that affect Microsoft Office and standalone Office products, including four defects the company described as more likely to be exploited.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-july-2025/