Headlines
Microsoft issued patches for 137 CVE-rated vulnerabilities:
- There are no exploited vulnerabilities within the patch release
- There is one (publicly known) Zero Day in SQL Server
- Several remote code execution vulnerabilities in Office
Quorum Cyber Recommendations
Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.
Microsoft Release Notes
July 2025 Security Updates – Release Notes – Security Update Guide – Microsoft
Key Vulnerability Details
| Title | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE | CVE-2025-49719 |
| CVSS | 7.5 |
| Reason for Concern | Publicly disclosed zero day |
| Mitigations and other Factors | An attacker would need to communicate with a target SQL server over the network. |
| Commentary | While this has been publicly disclosed before patching, there are no reports to indicate that it has been exploited. |
| Threat Intelligence Comment | CVE-2025-49719 is a publicly disclosed zero-day vulnerability with a severity score of 7.5, affecting SQL servers by allowing attackers to exploit the system over the network. There have been no confirmed instances of exploitation in the wild. This vulnerability requires attackers to establish network communication with the target SQL server, potentially enabling unauthorised access or manipulation of database operations. |
| Link | CVE-2025-49719 – Security Update Guide – Microsoft – Microsoft SQL Server Information Disclosure Vulnerability |
| Title | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
| CVE | CVE-2025-47981 |
| CVSS | 9.8 |
| Reason for Concern | This is the only Critical-rated vulnerability addressed by Microsoft this month. |
| Mitigations and other Factors | An attacker would need to communicate with the target server over the network for the exploit to work. The following GPO needs to be enabled: “Network security: Allow PKU2U authentication requests to this computer to use online identities“. |
| Commentary | Vulnerability affects Windows 10 machines running 1607 or above. |
| Threat Intelligence Comment | CVE-2025-47981 is a critical remote code execution vulnerability in the SPNEGO Extended Negotiation (NEGOEX) security mechanism, with a severity score of 9.8, marking it as the only critical vulnerability addressed by Microsoft this month. Exploitation requires network communication with the target server and the enabling of the Group Policy Object (GPO) “Network security: Allow PKU2U authentication requests to this computer to use online identities”. This vulnerability potentially allows attackers to execute arbitrary code on vulnerable systems. |
| Link | CVE-2025-47981 – Security Update Guide – Microsoft – SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
| Title | Microsoft Office Remote Code Execution Vulnerability |
| CVE | CVE-2025-49695 |
| CVSS | 8.4 |
| Reason for Concern | The preview pane in Outlook can be used as an attack vector for this vulnerability. |
| Mitigations and other Factors | User interaction is required for exploitation. |
| Commentary | There have been several vulnerabilities of this type in the last few months. Exploitation via the email preview pane appears to be increasingly common. |
| Threat Intelligence Comment | CVE-2025-49695 is a remote code execution vulnerability in Microsoft Office, with a severity score of 8.4. It can be exploited through the Outlook preview pane, which serves as an attack vector, although user interaction is required for successful exploitation. This type of vulnerability has been observed several times in recent months, with a growing trend of attacks leveraging the email preview pane for exploitation. Users are advised to exercise caution when handling emails and apply available patches promptly to protect against potential attacks. |
| Link | CVE-2025-49695 – Security Update Guide – Microsoft – Microsoft Office Remote Code Execution Vulnerability |












