KB5058716: Fixes an issue in which uninitialized memory can be read in some rare cases
KB5058716 - Description of the security update for SQL Server 2017 GDR
July 8, 2025
Summary
This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:
- CVE-2025-49719 - Microsoft SQL Server Information Disclosure Vulnerability
The Microsoft SQL Server components are updated to the following builds in this security update: - SQL Server - Product version: 14.0.2075.8, file version: 2017.140.2075.8
Improvements and fixes included in this update
- 4053196:Fixes an issue in which uninitialized memory can be read in some rare cases when using variable length parameters.
4241790:Fixes an issue that was introduced in a previous Windows update that causes restarts and prevents Setup from continuing. After you apply this fix, the value of the PendingFileRenameOperations registry key is deleted when you apply updates to SQL Server.