Spoofing Vulnerability in JDBC Driver for SQL Server by Microsoft
CVE-2025-59250

8.1HIGH

What is CVE-2025-59250?

The JDBC Driver for SQL Server contains improper input validation that may allow unauthorized attackers to spoof user identities over a network. This vulnerability highlights potential security weaknesses that could be exploited to impersonate users or manipulate database interactions. It is crucial for organizations utilizing the JDBC Driver to assess and address this vulnerability to safeguard their systems from unauthorized access.

Affected Version(s)

Microsoft JDBC Driver for SQL Server 10.2 Unknown 1.0.0 < 10.2.4

Microsoft JDBC Driver for SQL Server 11.2 Unknown 1.0.0 < 11.2.4

Microsoft JDBC Driver for SQL Server 12.10 Unknown 1.0.0 < 12.10.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59250 : Spoofing Vulnerability in JDBC Driver for SQL Server by Microsoft