A critical zero-day vulnerability in Microsoft SQL Server, identified as CVE-2025-49719, allows unauthorized attackers to gain access to sensitive data over network connections.
See also: Chrome 138 update fixes Zero-Day vulnerability

The vulnerability results from insufficient input validation in SQL Server processing mechanisms, which allows disclosure of uninitialized memory contents without requiring authentication or user interaction. The vulnerability affects multiple versions of SQL Server from 2016 through 2022, and the relevant security updates were released on July 8, 2025 to address this important security issue.
The vulnerability CVE-2025-49719 has been classified under the category CWE-20: Improper Input Validation, which represents a fundamental flaw in the way SQL Server processes incoming network requests.
The vulnerability has a CVSS 3.1 base score of 7.5 and a temporary score of 6.5, classified as “Important” severity.
See also: Chrome zero-day allowed the development of the Trinper backdoor
The technical weakness allows attackers to exploit inadequate input validation procedures, resulting in potential access to uninitialized memory areas that may contain sensitive database information, connection strings, or other confidential data structures.

The characteristics of the attack vector make the vulnerability particularly concerning for enterprise environments.
The CVSS string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N indicates low-sophistication network-based attacks, requiring no user privileges or interaction. This configuration allows remote attackers to extract potentially sensitive information from network-accessible SQL Server instances, making them an attractive target for automated exploit tools and reconnaissance activities.
The exploitation mechanism is based on attacks carried out over a network without requiring identification credentials or user participation, which significantly lowers the barrier to attack success.
See also: Hackers exploit zero-day vulnerability in Windows WebDav
Microsoft has released full security updates to address the CVE-2025-49719 vulnerability in all supported versions of SQL Server. This vulnerability once again highlights the importance of proper login validation in applications and systems and the need to regularly monitor security advisories and respond promptly to critical updates.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
