PT-2025-28609 · Microsoft · Sql Server
Vladimir Aleksic
·
Published
2025-07-08
·
Updated
2025-07-17
·
CVE-2025-49719
7.8
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
**Name of the Vulnerable Software and Affected Versions:**
Microsoft SQL Server (affected versions not specified)
**Description:**
Improper input validation in Microsoft SQL Server allows an unauthorized attacker to disclose sensitive information over a network. The vulnerability, identified as CVE-2025-49719, has been publicly disclosed and is already being exploited in the wild. Approximately 2.9 million services are found to be affected yearly. The vulnerability allows a remote, unauthenticated attacker to access data from uninitialized memory.
**Recommendations:**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
LPE
Weakness Enumeration
Related Identifiers
Affected Products
References · 42
- https://bdu.fstec.ru/vul/2025-08327 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49719 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-49719 · Security Note
- https://twitter.com/CyberWolfGuard/status/1942994478098194929 · Twitter Post
- https://twitter.com/Prevent_Cyber/status/1942820850039918614 · Twitter Post
- https://twitter.com/_CYOPS/status/1942823941627633828 · Twitter Post
- https://twitter.com/socradar/status/1943247899908886548 · Twitter Post
- https://reddit.com/r/SQLServer/comments/1lv1js0/cve202549719_zero_day_information_disclosure · Reddit Post
- https://twitter.com/dailytechonx/status/1943078966199263577 · Twitter Post
- https://twitter.com/the_yellow_fall/status/1942768574667555132 · Twitter Post
- https://twitter.com/secured_cyber/status/1943753188286640503 · Twitter Post
- https://twitter.com/moton/status/1942715566479061323 · Twitter Post
- https://twitter.com/grok/status/1944011636089794850 · Twitter Post
- https://twitter.com/ws_bryan1/status/1942642426662818074 · Twitter Post
- https://twitter.com/ammik14/status/1942806120072171557 · Twitter Post