CVE-2025-59250: Microsoft Jdbc Driver For SQL Server

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

Affected products

  • Microsoft Jdbc Driver For SQL Server: from 10.2.0, before 10.2.4 (fixed in 10.2.4); from 11.2.0, before 11.2.4 (fixed in 11.2.4); from 12.2.0, before 12.2.1 (fixed in 12.2.1); from 12.4.0, before 12.4.3 (fixed in 12.4.3); from 12.6.0, before 12.6.5 (fixed in 12.6.5); from 12.8.0, before 12.8.2 (fixed in 12.8.2); …

Published 2025-10-14. Last modified 2026-06-17.