CVE-2025-49717: Microsoft SQL Server Remote Code Execution Vulnerability
Published Jul 8, 2025
·Updated
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
8 affected componentsFixes available
Microsoft SQL Server 2022 (CU 19)
Microsoft SQL Server 2019
Microsoft SQL Server 2022
Microsoft SQL Server 2019 (CU 32)
Microsoft SQL Server 2019>=15.0.2000.5<15.0.2135.5
Microsoft SQL Server 2019>=15.0.4003.23<15.0.4435.7
Microsoft SQL Server 2022>=16.0.1000.6<16.0.1140.6
Microsoft SQL Server 2022>=16.0.4003.1<16.0.4200.1
Event History
Dec 10, 2024
News Published
08:48 PM
Jul 8, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
11:01 PM
Sep 10, 2025
News Published
via The Register·03:31 AM
News Published
via The Register·03:36 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-49717?
CVE-2025-49717 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2025-49717?
To fix CVE-2025-49717, apply the latest security updates or patches provided by Microsoft for affected SQL Server versions.
3
Which versions of SQL Server are affected by CVE-2025-49717?
CVE-2025-49717 affects Microsoft SQL Server 2019 (CU 32), SQL Server 2022 (CU 19), and their respective GDR versions.
4
What type of vulnerability is CVE-2025-49717?
CVE-2025-49717 is classified as a heap-based buffer overflow vulnerability.
5
Can unauthorized users exploit CVE-2025-49717?
CVE-2025-49717 requires an authorized user to exploit the vulnerability, making it less accessible to unauthorized attackers.