
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59250 is an improper input validation vulnerability in the Microsoft JDBC Driver for SQL Server that allows an unauthenticated network attacker to perform spoofing attacks. Disclosed on October 14, 2025, as part of Microsoft's October 2025 Patch Tuesday, it affects multiple driver versions: 10.2.x before 10.2.4, 11.2.x before 11.2.4, 12.2.x before 12.2.1, 12.4.x before 12.4.3, 12.6.x before 12.6.5, 12.8.x before 12.8.2, 12.10.x before 12.10.2, and 13.2.x before 13.2.1. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), requiring user interaction but no privileges (Microsoft MSRC, Oracle CPU Jan 2026).
The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in the JDBC Driver for SQL Server's handling of network input. Due to insufficient validation, an attacker positioned on the network can craft malicious responses or connection data to impersonate a legitimate SQL Server, deceiving client applications or users into trusting a malicious connection. Exploitation requires user interaction (e.g., a user or application initiating a database connection), but no authentication or special privileges are needed on the attacker's part. No public technical write-up or proof-of-concept code has been identified (Microsoft MSRC, Oracle CPU Jan 2026).
Successful exploitation allows an attacker to impersonate a legitimate SQL Server endpoint, resulting in high confidentiality and high integrity impact — attackers could intercept sensitive database credentials or data, and manipulate data exchanged between the client and what it believes to be a trusted server. There is no availability impact. Affected environments include any application using a vulnerable version of the Microsoft JDBC Driver for SQL Server, including downstream products such as Oracle GoldenGate Big Data and Application Adapters, IBM Business Automation Manager Open Editions, IBM Instana Observability, IBM watsonx Orchestrate, and Splunk AppDynamics Database Agent (Microsoft MSRC, Oracle CPU Jan 2026, IBM Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the latest available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.075%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported (Microsoft MSRC).
Microsoft has released patched versions of the JDBC Driver for SQL Server addressing this vulnerability: 10.2.4, 11.2.4, 12.2.1, 12.4.3, 12.6.5, 12.8.2, 12.10.2, and 13.2.1. Organizations should upgrade to the appropriate fixed version as soon as possible. Additionally, implementing strict TLS certificate validation and verifying server identity during connection establishment can reduce exposure. IBM has released updates for affected products (Business Automation Manager Open Editions, Instana Observability, watsonx Orchestrate), and Splunk has addressed the issue in AppDynamics Database Agent via their March 2026 advisory. Oracle addressed the vulnerability in the January 2026 Critical Patch Update for GoldenGate Big Data and Application Adapters (Microsoft MSRC, Oracle CPU Jan 2026, IBM Advisory, Splunk Advisory).
CVE-2025-59250 was noted in coverage of Microsoft's October 2025 Patch Tuesday, which addressed 172 flaws including 6 zero-days, though this particular vulnerability did not receive significant individual attention given its lower exploitation likelihood. Security outlets such as BleepingComputer and Zero Day Initiative covered the broader Patch Tuesday release. The SANS Internet Storm Center also referenced the update cycle in which this CVE appeared (BleepingComputer, ZDI Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."