Published On: Jul 11, 2025 08:32
Advisory No: TZCERT-SA-25-0107
Source: Microsoft
Software Affected: Microsoft SQL Server 2016, 2017, 2019, 2022 (all supported versions)
CVE‑2025‑49719 is an important information disclosure vulnerability in Microsoft SQL Server, rated with a CVSS 3.1 score of 7.5, that allows unauthenticated, remote attackers to leak uninitialized memory from the SQL Server process over the network.
This flaw stems from improper input validation in the SQL Server engine’s handling of TCP requests (default port 1433). An attacker can send a specially crafted login or network packet to the database server, which triggers the disclosure of uninitialized memory contents. This may expose sensitive information such as credentials, database schemas, connection strings, or cryptographic keys. No authentication or user interaction is required for exploitation, making it a low-barrier reconnaissance and information-gathering vulnerability.
While Microsoft’s Exploitability Index considers the likelihood of real-world attacks to be "Less Likely", the potential impact is significant, particularly for publicly accessible SQL Server instances or those in cloud environments with weak network segmentation. Exposure of uninitialized memory could reveal critical secrets and facilitate further attacks.
Microsoft has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.