Microsoft fixes over 130 flaws, no actively exploited zero-days

Microsoft fixes over 130 flaws, no actively exploited zero-days

Microsoft has released its July 2025 Patch Tuesday security updates, addressing more than 130 vulnerabilities across its products. Among the fixes is a patch for a previously disclosed vulnerability in Microsoft SQL Server.

The flaw, tracked as CVE-2025-49719, is an information disclosure flaw in SQL Server that could allow a remote, unauthenticated attacker to access sensitive data by reading uninitialized memory.

The issue is related to improper input validation, enabling unauthorized access to data over a network. Administrators are advised to install the latest version of Microsoft SQL Server along with either version 18 or 19 of the Microsoft OLE DB Driver.

July 2025 Patch Tuesday also fixes a number of high-risk vulnerabilities affecting Microsoft Excel and Office, Microsoft NEGOEX, Microsoft Visual Studio Code Python Extension, and other software products.


Back to the list

Latest Posts

AI voice impersonator posed as US Secretary of State Marco Rubio to contact foreign ministers

AI voice impersonator posed as US Secretary of State Marco Rubio to contact foreign ministers

The impersonator contacted the targets in mid-June using the encrypted messaging app Signal.
9 July 2025
DoNot APT targets European foreign affairs ministry in espionage campaign

DoNot APT targets European foreign affairs ministry in espionage campaign

The attack used a malicious Google Drive link, which delivered a RAR archive containing malware previously linked to the DoNot APT.
9 July 2025
Microsoft fixes over 130 flaws, no actively exploited zero-days

Microsoft fixes over 130 flaws, no actively exploited zero-days

Among the fixes is a patch for a previously disclosed vulnerability in Microsoft SQL Server.
9 July 2025