Use of uninitialized resource in Microsoft SQL Server - CVE-2025-49718

 

Use of uninitialized resource in Microsoft SQL Server - CVE-2025-49718

Published: July 9, 2025


Vulnerability identifier: #VU112568
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49718
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources in Microsoft SQL Server. A remote attacker can pass specially crafted data to the application, trigger uninitialized usage of resources and gain access to sensitive information on the system.


Affected software

Microsoft SQL Server
Tenable Identity Exposure (formerly Tenable.ad)

How to mitigate CVE-2025-49718

Install updates from vendor's website.

Microsoft SQL Server - addressed in versions 15.0.2135.5 15.0.2135.5, 15.0.4435.7, 16.0.1140.6, 16.0.4200.1 16.0.4200.1
Tenable Identity Exposure (formerly Tenable.ad) - update to 3.77.14

External References

Related Security Bulletins