Spoofing Vulnerability in JDBC Driver for SQL Server by Microsoft
CVE-2025-59250
8.1HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-59250?
The JDBC Driver for SQL Server contains improper input validation that may allow unauthorized attackers to spoof user identities over a network. This vulnerability highlights potential security weaknesses that could be exploited to impersonate users or manipulate database interactions. It is crucial for organizations utilizing the JDBC Driver to assess and address this vulnerability to safeguard their systems from unauthorized access.
Affected Version(s)
Microsoft JDBC Driver for SQL Server 10.2 Unknown 1.0.0 < 10.2.4
Microsoft JDBC Driver for SQL Server 11.2 Unknown 1.0.0 < 11.2.4
Microsoft JDBC Driver for SQL Server 12.10 Unknown 1.0.0 < 12.10.2
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved