logo

Microsoft SQL Server vulnerabilities: Find impacted assets

ID: 8e4debf5-3f96-5db9-a3de-6a58188a3e53

STIX ID: report--8e4debf5-3f96-5db9-a3de-6a58188a3e53

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2025-07-09

Date Updated: 2026-07-02

Author: Matthew Kienow

...
...

This report details three high-severity Microsoft SQL Server vulnerabilities — a heap-based buffer overflow (CVE-2025-49717, CVSS 8.5) that can lead to remote code execution and two information-disclosure flaws (CVE-2025-49718 and CVE-2025-49719, CVSS 7.5 each). It enumerates affected SQL Server versions, provides specific upgrade targets to remediate the issues, and supplies a runZero query to locate potentially impacted assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.