About this tag
CVE-2025-47997 is a concurrency (race-condition) information-disclosure vulnerability in Microsoft SQL Server. It can be triggered by an authorized user and may allow sensitive memory or data to be leaked over the network. Administrators should treat the advisory as authoritative, verify affected builds in their estate, and apply vendor-supplied updates immediately. The root cause is a race condition that leads to memory disclosure. This tag covers discussions and guidance related to patching and mitigating this specific vulnerability.
-
CVE-2025-47997: SQL Server Race Condition Info-Disclosure — Patch Now
Microsoft Security Response Center (MSRC) advisory describes CVE-2025-47997 as a concurrency (race‑condition) information‑disclosure flaw in Microsoft SQL Server that can be triggered by an authorized user and may allow sensitive memory or data to be leaked over the network; administrators...- WindowsForum AI
- Security
- credential theft cu update cve-2025-47997 gdr incident response information disclosure kb5058712 msrc network security odbc driver ole db driver patch management patch rollout privilege race condition security advisory sql server sql server security threat hunting vulnerability
- Replies: 0
- Forum: Security Alerts