- Description
- Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- secure@microsoft.com
- CWE-122
- Hype score
- Not currently trending
⚠️Actualizaciones de seguridad de julio de Microsoft ❗CVE-2025-47981 ❗CVE-2025-47986 ❗CVE-2025-49753 ➡️Más info: https://t.co/CAnRcgRlHV https://t.co/GixMnNjlWr
@CERTpy
10 Jul 2025
202 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windows SPNEGO Nightmare: Critical RCE Vulnerability CVE-2025-47981 Unveiled https://t.co/XZrO6XlmLR
@endi24
10 Jul 2025
931 Impressions
8 Retweets
10 Likes
3 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨🚨 #Windows #Vulnerability #Serious CVE-2025-47981 Go patch your systems NOW. https://t.co/oh16Bvez6H
@thepsharp
10 Jul 2025
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft、7月の月例パッチで緊急性の高い脆弱性を多数修正、特にNEGOEX脆弱性に注意(CVE-2025-47981) #セキュリティ対策Lab #セキュリティ #Security https://t.co/HsrFR3IeLY
@securityLab_jp
9 Jul 2025
103 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🐛 Attention, Windows users! A critical patch for CVE-2025-47981 is here to save you from a wormable RCE disaster. Don't let those pesky bugs crash your party—update now! #WindowsForum #SecurityPatch #StaySafe https://t.co/nuJc6rl9FH
@windowsforum
9 Jul 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Attention, Windows users! Patch Tuesday brought a critical fix for the wormable RCE vulnerability CVE-2025-47981. Don't let your system be the next snack for cyber worms! 🐛💻 #WindowsForum #PatchTuesday #StaySafe https://t.co/LVUtDp2w9I
@windowsforum
9 Jul 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-47981: The next WannaCry? 😱 Critical RCE in Windows SPNEGO NEGOEX (CVSS 9.8), "wormable." Patch now! 🛡️ #CyberSec #Windows #WannaCry Link: https://t.co/hbGGh7Rv1a
@_F2po_
9 Jul 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-47981 : un nouveau WannaCry ? 😱 Cette vulnérabilité critique RCE dans Windows SPNEGO NEGOEX (CVSS 9.8) est "wormable". Patch d’urgence dispo ! 🛡️ #CyberSec #Windows #WannaCry Lien : https://t.co/hbGGh7S2QI
@_F2po_
9 Jul 2025
124 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical #Windows Security Bug Opens Door to Remote Attacks: #CVE-2025-47981 Under Fire https://t.co/VJkPfgQKA8
@UndercodeNews
9 Jul 2025
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A severe buffer overflow vulnerability, CVE-2025-47981, has been discovered in Windows SPNEGO, scoring a critical 9.8 on the CVSS scale. Attackers can execute remote code without user interaction, threatening enterprise environments, so immediate patch deployment is essential.
@CybrPulse
9 Jul 2025
131 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Microsoft Patch Tuesday security updates for July 2025 fixed a zero-day Microsoft's July 2025 Patch Tuesday fixed 130 vulnerabilities across Windows, Office, .NET, Azure, Teams, and more. Ten flaws are rated Critical, including CVE-2025-47981, a wormable RCE in SPNEGO NEGOEX htt
@dCypherIO
9 Jul 2025
186 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐛 July Patch Tuesday is here! Microsoft tackled 130 vulnerabilities, but watch out for CVE-2025-47981—a wormable bug ready to crash the party! Time for admins to suit up and patch those holes! #WindowsForum #PatchTuesday #Security https://t.co/RPXUzZKNvP
@windowsforum
9 Jul 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) https://t.co/MpiaJOCxp7 #HelpNetSecurity #Cybersecurity https://t.co/qRudWFgAWV
@PoseidonTPA
9 Jul 2025
97 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s July Patch Tuesday fixes 130 vulnerabilities. Top issues: CVE-2025-47981 – SPNEGO RCE, likely wormable CVE-2025-49719 – SQL Server info leak, publicly known Also impacts Office, Hyper-V, BitLocker Patch now to stay protected #CyberSecurity #PatchTuesday #C
@CloneSystemsInc
9 Jul 2025
206 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) https://t.co/O4YIKWSeJE https://t.co/ZUI7uvKjSQ
@evanderburg
9 Jul 2025
118 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "9D58CEDA-0611-4E21-87AF-C368F45BB685",
"versionEndExcluding": "10.0.10240.21073"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "1EEA1F09-0FA7-4946-8005-F0CF177B1103",
"versionEndExcluding": "10.0.10240.21073"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "3CEAC32A-5246-4F6B-8DD5-E49F3BA621DA",
"versionEndExcluding": "10.0.14393.8246"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "E0A0243D-52B4-49AE-B1AE-263640C492B0",
"versionEndExcluding": "10.0.14393.8246"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "2062C268-282B-4E52-9F8C-876A2D483EAD",
"versionEndExcluding": "10.0.17763.7558"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "00FCA704-C6E0-4DE4-86F0-80552527AE53",
"versionEndExcluding": "10.0.17763.7558"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50848190-CF61-47F6-90B8-DB0C120749F5",
"versionEndExcluding": "10.0.19044.6093"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01E62E99-5EDA-487C-A941-E2DA348B501F",
"versionEndExcluding": "10.0.19045.6093"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76FEE1E8-EB22-4E01-86D7-13B35F9D2876",
"versionEndExcluding": "10.0.22621.5624"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19D0DAB7-4BFF-4BB7-9E0E-B020CF8573C9",
"versionEndExcluding": "10.0.22631.5624"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E866DB2-9CA7-4BCC-8591-9BC94300B779",
"versionEndExcluding": "10.0.26100.4652"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6FA4941-0641-4EA0-99A8-97121F625380",
"versionEndExcluding": "10.0.14393.8246"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCFD9FA0-D149-422A-975C-582C9BC9024D",
"versionEndExcluding": "10.0.17763.7558"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE46D39E-7048-4A31-9753-39F6E5F97D1D",
"versionEndExcluding": "10.0.20348.3932"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "613302B8-D5C2-4908-9FC9-0EC1650D4517",
"versionEndExcluding": "10.0.25398.1732"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10E640FB-32AB-45B6-BC42-56CC587C0A35",
"versionEndExcluding": "10.0.26100.4652"
}
],
"operator": "OR"
}
]
}
]