Microsoft has released critical security updates to address CVE-2025-47981, a severe heap-based buffer overflow vulnerability in the SPNEGO Extended Negotiation (NEGOEX) Security Mechanism that affects multiple Windows and Windows Server versions. Microsoft released comprehensive security updates on July 8, 2025, addressing the vulnerability across different Windows configurations. The vulnerability particularly affects Windows client machines running Windows 10 version 1607 and above, where the Group Policy Object “Network security: Allow PKU2U authentication requests to this computer to use online identities” is enabled by default. Heap-based buffer overflow vulnerability in Windows SPNEGO with 9.8/10 CVSS score enabling remote code execution.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 09 Jul 2025 13:55:14 +0000