cbcvebase.
CVE-2025-47981
published 2025-07-08

CVE-2025-47981: Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
21.88%
97.4th percentile
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2107310.0.10240.21073
microsoftwindows_10_1607< 10.0.14393.824610.0.14393.8246
microsoftwindows_10_1809< 10.0.17763.755810.0.17763.7558
microsoftwindows_10_21h2< 10.0.19044.609310.0.19044.6093
microsoftwindows_10_22h2< 10.0.19045.609310.0.19045.6093
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2107310.0.10240.21073
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.824610.0.14393.8246
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.755810.0.17763.7558
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.609310.0.19044.6093
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.609310.0.19045.6093
microsoftwindows_11_22h2< 10.0.22621.562410.0.22621.5624
microsoftwindows_11_23h2< 10.0.22631.562410.0.22631.5624
microsoftwindows_11_24h2< 10.0.26100.465210.0.26100.4652
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.562410.0.22621.5624
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.562410.0.22631.5624
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.562410.0.22631.5624
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.465210.0.26100.4652
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.278206.1.7601.27820
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.255736.2.9200.25573
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.226766.3.9600.22676
microsoftwindows_server_2016< 10.0.14393.824610.0.14393.8246
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.824610.0.14393.8246
microsoftwindows_server_2019< 10.0.17763.755810.0.17763.7558

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a malicious NEGOEX/SPNEGO message sent over the network to a target server; monitor for anomalous SPNEGO Extended Negotiation (NEGOEX) traffic, especially malformed or oversized negotiation tokens that could trigger a heap-based buffer overflow.
  • The vulnerability is exploitable on Windows client machines where the GPO 'Network security: Allow PKU2U authentication requests to this computer to use online identities' is enabled (default on Windows 10 1607+). Audit and monitor PKU2U authentication activity as a detection pivot.
  • ·The GPO 'Network security: Allow PKU2U authentication requests to this computer to use online identities' is enabled by default on Windows 10 version 1607 and above, making those systems vulnerable by default. Disabling this GPO can serve as a mitigation where patching is not immediately possible.
  • ·Exploitation is rated 'More Likely' by Microsoft for the latest software release, despite no confirmed in-the-wild exploitation at time of disclosure. Prioritize patching accordingly.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.