Input validation error in Microsoft SQL Server - CVE-2025-49719
Published: July 9, 2025
Vulnerability identifier: #VU112566
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49719
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information on the system.
The vulnerability exists due to insufficient validation of user-supplied input in Microsoft SQL Server. A remote attacker can pass specially crafted input to the application and disclose sensitive information.
Affected software
Microsoft SQL Server
Tenable Identity Exposure (formerly Tenable.ad)
Tenable Identity Exposure (formerly Tenable.ad)
How to mitigate CVE-2025-49719
Install updates from vendor's website.
Microsoft SQL Server - addressed in versions 13.0.6460.7 13.0.6460.7, 13.0.7055.9 13.0.7055.9, 14.0.2075.8 14.0.2075.8, 14.0.3495.9 14.0.3495.9, 15.0.2135.5 15.0.2135.5, 15.0.4435.7, 16.0.1140.6, 16.0.4200.1 16.0.4200.1
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.14
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.14