Heap-Based Buffer Overflow in Windows SPNEGO Extended Negotiation
CVE-2025-47981

9.8CRITICAL

Key Information:

Badges

💰 Ransomware👾 Exploit Exists📰 News Worthy

What is CVE-2025-47981?

CVE-2025-47981 is a critical vulnerability affecting the Windows SPNEGO Extended Negotiation, which is an integral part of Microsoft’s security infrastructure that facilitates authentication processes. This vulnerability arises from a heap-based buffer overflow, allowing unauthorized attackers to execute arbitrary code over a network. If exploited, it can compromise the confidentiality, integrity, and availability of the affected system, enabling attackers to manipulate data or gain unauthorized access to sensitive information. The implications of such exploitation can severely undermine organizational security and operational continuity.

Potential Impact of CVE-2025-47981

  1. Remote Code Execution: The vulnerability permits attackers to execute malicious code remotely, which can lead to the complete takeover of affected systems, potentially facilitating further attacks or data exfiltration.

  2. Unauthorized Access: Exploitation can result in unauthorized access to sensitive information and resources, exposing organizations to data breaches and potential compliance violations.

  3. Network Compromise: The ability to execute code remotely can allow attackers to spread malware within an organization’s network, leading to broader system compromises and increased risks of ransomware attacks.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21073

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8246

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7558

News Articles

Week in review: Microsoft fixes wormable RCE bug on Windows, check for CitrixBleed 2 exploitation - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes critical wormable Windows flaw

2 weeks ago

Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) - Help Net Security

Microsoft has patched a public SQL Server flaw (CVE-2025-49719) and a wormable RCE bug on Windows and Windows Server (CVE-2025-47981).

3 weeks ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź’°

    Used in Ransomware

  • 👾

    Exploit known to exist

  • đź“°

    First article discovered by Help Net Security

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47981 : Heap-Based Buffer Overflow in Windows SPNEGO Extended Negotiation