Junglewise Threat Intelligence

CVE-2025-59250: Microsoft JDBC Driver for SQL Server spoofing via improper input validation

CVE-2025-59250 · Severity: high · CVSS 8.1 · Published 2025-10-14

Vendors: Microsoft.

Executive brief

Microsoft's JDBC Driver for SQL Server contains an improper input validation flaw that allows an attacker to spoof connections over a network without authentication. Affected applications using vulnerable versions of this database driver could have their SQL Server communications compromised, enabling attackers to impersonate legitimate database connections and potentially access or modify sensitive data.

Technical details

The vulnerability is a CWE-20 improper input validation flaw in the JDBC Driver for SQL Server that enables spoofing attacks. The affected driver versions are: 8.3.0–10.2.3 (jre11-preview), 11.2.0–11.2.3, 12.2.0, 12.6.0–12.6.4, 12.8.0–12.8.1, 12.10.0–12.10.1, and 13.2.0 (all jre11 variants). The attack is network-reachable and requires no privileges, but does require user interaction. The attacker can achieve high impact to both confidentiality and integrity of database communications. Patches are available in versions: 10.2.4, 11.2.4, 12.2.1, 12.6.5, 12.8.2, 12.10.2, and 13.2.1 (jre11 variants).

Affected products

  • Microsoft JDBC Driver for SQL Server 8.3.0-jre11-preview through 10.2.3-jre11; 11.2.0-jre11 through 11.2.3-jre11; 12.2.0-jre11; 12.6.0-jre11 through 12.6.4-jre11; 12.8.0-jre11 through 12.8.1-jre11; 12.10.0-jre11 through 12.10.1-jre11; 13.2.0-jre11

Timeline

  • 2025-10-14: disclosed: Vulnerability published to GitHub Advisory Database and NVD
  • 2025-10-14: patched: Patches available in versions 10.2.4, 11.2.4, 12.2.1, 12.6.5, 12.8.2, 12.10.2, and 13.2.1 (jre11 variants)

References