CVE-2025-59250

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
microsoftCNA
8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
microsoftjdbc_driver_for_sql_server
10.2.0 ≤
𝑥
< 10.2.4
microsoftjdbc_driver_for_sql_server
11.2.0 ≤
𝑥
< 11.2.4
microsoftjdbc_driver_for_sql_server
12.2.0 ≤
𝑥
< 12.2.1
microsoftjdbc_driver_for_sql_server
12.4.0 ≤
𝑥
< 12.4.3
microsoftjdbc_driver_for_sql_server
12.6.0 ≤
𝑥
< 12.6.5
microsoftjdbc_driver_for_sql_server
12.8.0 ≤
𝑥
< 12.8.2
microsoftjdbc_driver_for_sql_server
12.10.0 ≤
𝑥
< 12.10.2
microsoftjdbc_driver_for_sql_server
13.2.0 ≤
𝑥
< 13.2.1
𝑥
= Vulnerable software versions