CVE detail
CVE-2025-49717
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
- Microsoft fixes critical wormable Windows flaw (CVE-2025-47981)Help Net Security
For July 2025 Patch Tuesday, Microsoft has released patches for 130 vulnerabilities, among them one that’s publicly disclosed (CVE-2025-49719) and a wormable RCE bug on Windows and Windows Server (CVE-2025-47981). CVE-2025-49719 and CVE-2025-49717, in Microsoft SQL Server CVE-2025-49719 is an uninitialized memory disclosure vulnerability affecting Microsoft SQL Server, which can be remotely triggered by unauthorized attackers. Microsoft says that exploit code for it is “unproven” – i.e., not publicly available or simply theoretical – and … More →
newswww.helpnetsecurity.comJul 9, 2025, 11:30 AM - July Patch Tuesday: 14 critical Microsoft vulnerabilities, one SAP hole rated at 10 in severityCSO Online
Microsoft’s July Patch Tuesday fixes are a mix of good news and bad news for CSOs: Fourteen of the vulnerabilities are rated as critical, but on the other hand, there are no zero-days and only one vulnerability with a publicly available proof of concept. CSOs need to immediately address a heap-based buffer overflow vulnerability in […]
newswww.csoonline.comJul 8, 2025, 11:50 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-37335CVSS 8.8 · High
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
- CVE-2024-26191CVSS 8.8 · High
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
- CVE-2024-38088CVSS 8.8 · High
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37334CVSS 8.8 · High
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2024-37333CVSS 8.8 · High
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-37332CVSS 8.8 · High
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability