CVE detail
CVE-2025-49719
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- 14th July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 14th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES McDonald’s has suffered a data breach that resulted in the exposure of chat transcripts, session tokens, and personal data from more than 64 million job applications submitted through its AI powered McHire […]
vendorresearch.checkpoint.comJul 14, 2025, 12:37 PM - Week in review: Microsoft fixes wormable RCE bug on Windows, check for CitrixBleed 2 exploitationHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) For July 2025 Patch Tuesday, Microsoft has released patches for 130 vulnerabilities, among them one that’s publicly disclosed (CVE-2025-49719) and a wormable RCE bug on Windows and Windows Server (CVE-2025-47981). Check for CitrixBleed 2 exploitation even if you patched quickly! (CVE-2025-5777) With PoC exploits for CVE-2025-5777 (aka CitrixBleed 2) now public and reports … More →
newswww.helpnetsecurity.comJul 13, 2025, 7:15 AM - Microsoft fixes critical wormable Windows flaw (CVE-2025-47981)Help Net Security
For July 2025 Patch Tuesday, Microsoft has released patches for 130 vulnerabilities, among them one that’s publicly disclosed (CVE-2025-49719) and a wormable RCE bug on Windows and Windows Server (CVE-2025-47981). CVE-2025-49719 and CVE-2025-49717, in Microsoft SQL Server CVE-2025-49719 is an uninitialized memory disclosure vulnerability affecting Microsoft SQL Server, which can be remotely triggered by unauthorized attackers. Microsoft says that exploit code for it is “unproven” – i.e., not publicly available or simply theoretical – and … More →
newswww.helpnetsecurity.comJul 9, 2025, 11:30 AM - July Patch Tuesday: 14 critical Microsoft vulnerabilities, one SAP hole rated at 10 in severityCSO Online
Microsoft’s July Patch Tuesday fixes are a mix of good news and bad news for CSOs: Fourteen of the vulnerabilities are rated as critical, but on the other hand, there are no zero-days and only one vulnerability with a publicly available proof of concept. CSOs need to immediately address a heap-based buffer overflow vulnerability in […]
newswww.csoonline.comJul 8, 2025, 11:50 PM Patch Tuesday July 2025: Microsoft rolled out fixes for 130 vulnerabilities, including a zero-day in SQL Server.
newswww.securityweek.comJul 8, 2025, 9:09 PMMicrosoft released Patch Tuesday security updates for July 2025, which addressed 130 flaws, including one a Microsoft SQL Server zero-day. Microsoft Patch Tuesday security updates for July 2025 addressed 130 vulnerabilities in Windows and Windows Components, Office and Office Components, .NET and Visual Studio, Azure, Teams, Hyper-V, Windows BitLocker, Microsoft Edge (Chromium-based), and the Windows […]
newssecurityaffairs.comJul 8, 2025, 9:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-37965CVSS 8.8 · High
Microsoft SQL Server Elevation of Privilege Vulnerability
- CVE-2026-47295CVSS 8.8 · High
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-54118CVSS 8.8 · High
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-54117CVSS 8.8 · High
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-47296CVSS 7.8 · High
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-40370CVSS 8.8 · High
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.