CVE-2025-47981

Published Jul 8, 2025

Last updated 4 days ago

Overview

Description
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score
Not currently trending
  1. ⚠️Actualizaciones de seguridad de julio de Microsoft ❗CVE-2025-47981 ❗CVE-2025-47986 ❗CVE-2025-49753 ➡️Más info: https://t.co/CAnRcgRlHV https://t.co/GixMnNjlWr

    @CERTpy

    10 Jul 2025

    202 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Windows SPNEGO Nightmare: Critical RCE Vulnerability CVE-2025-47981 Unveiled https://t.co/XZrO6XlmLR

    @endi24

    10 Jul 2025

    931 Impressions

    8 Retweets

    10 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨🚨🚨🚨 #Windows #Vulnerability #Serious CVE-2025-47981 Go patch your systems NOW. https://t.co/oh16Bvez6H

    @thepsharp

    10 Jul 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Microsoft、7月の月例パッチで緊急性の高い脆弱性を多数修正、特にNEGOEX脆弱性に注意(CVE-2025-47981) #セキュリティ対策Lab #セキュリティ #Security https://t.co/HsrFR3IeLY

    @securityLab_jp

    9 Jul 2025

    103 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🐛 Attention, Windows users! A critical patch for CVE-2025-47981 is here to save you from a wormable RCE disaster. Don't let those pesky bugs crash your party—update now! #WindowsForum #SecurityPatch #StaySafe https://t.co/nuJc6rl9FH

    @windowsforum

    9 Jul 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Attention, Windows users! Patch Tuesday brought a critical fix for the wormable RCE vulnerability CVE-2025-47981. Don't let your system be the next snack for cyber worms! 🐛💻 #WindowsForum #PatchTuesday #StaySafe https://t.co/LVUtDp2w9I

    @windowsforum

    9 Jul 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CVE-2025-47981: The next WannaCry? 😱 Critical RCE in Windows SPNEGO NEGOEX (CVSS 9.8), "wormable." Patch now! 🛡️ #CyberSec #Windows #WannaCry Link: https://t.co/hbGGh7Rv1a

    @_F2po_

    9 Jul 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-2025-47981 : un nouveau WannaCry ? 😱 Cette vulnérabilité critique RCE dans Windows SPNEGO NEGOEX (CVSS 9.8) est "wormable". Patch d’urgence dispo ! 🛡️ #CyberSec #Windows #WannaCry Lien : https://t.co/hbGGh7S2QI

    @_F2po_

    9 Jul 2025

    124 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Critical #Windows Security Bug Opens Door to Remote Attacks: #CVE-2025-47981 Under Fire https://t.co/VJkPfgQKA8

    @UndercodeNews

    9 Jul 2025

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. A severe buffer overflow vulnerability, CVE-2025-47981, has been discovered in Windows SPNEGO, scoring a critical 9.8 on the CVSS scale. Attackers can execute remote code without user interaction, threatening enterprise environments, so immediate patch deployment is essential.

    @CybrPulse

    9 Jul 2025

    131 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Microsoft Patch Tuesday security updates for July 2025 fixed a zero-day Microsoft's July 2025 Patch Tuesday fixed 130 vulnerabilities across Windows, Office, .NET, Azure, Teams, and more. Ten flaws are rated Critical, including CVE-2025-47981, a wormable RCE in SPNEGO NEGOEX htt

    @dCypherIO

    9 Jul 2025

    186 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🐛 July Patch Tuesday is here! Microsoft tackled 130 vulnerabilities, but watch out for CVE-2025-47981—a wormable bug ready to crash the party! Time for admins to suit up and patch those holes! #WindowsForum #PatchTuesday #Security https://t.co/RPXUzZKNvP

    @windowsforum

    9 Jul 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) https://t.co/MpiaJOCxp7 #HelpNetSecurity #Cybersecurity https://t.co/qRudWFgAWV

    @PoseidonTPA

    9 Jul 2025

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Microsoft’s July Patch Tuesday fixes 130 vulnerabilities. Top issues: CVE-2025-47981 – SPNEGO RCE, likely wormable CVE-2025-49719 – SQL Server info leak, publicly known Also impacts Office, Hyper-V, BitLocker Patch now to stay protected #CyberSecurity #PatchTuesday #C

    @CloneSystemsInc

    9 Jul 2025

    206 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Microsoft fixes critical wormable Windows flaw (CVE-2025-47981) https://t.co/O4YIKWSeJE https://t.co/ZUI7uvKjSQ

    @evanderburg

    9 Jul 2025

    118 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.