CVE-2025-47981 is a critical remote code execution vulnerability in the Windows SPNEGO Extended Negotiation (NEGOEX) Security Mechanism. The flaw is described as a heap-based buffer overflow in the NEGOEX protocol handling logic. A remote, unauthenticated attacker can trigger the condition by sending a specially crafted message to a vulnerable system over the network. The issue affects supported Windows client and server platforms, including Windows 10 version 1607 and later and Windows Server versions from 2008 R2 onward. Available reporting indicates the vulnerable SPNEGO-related functionality is enabled by default on affected Windows client systems through the PKU2U authentication policy setting, increasing exposure. The vulnerability has been assessed as critical with a CVSS v3.1 base score of 9.8 and has been characterized as potentially wormable because exploitation does not require user interaction or prior authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in the SPNEGO Extended Negotiation (NEGOEX) security mechanism reported as exploited.
A critical remote code execution vulnerability in the SPNEGO Extended Negotiation (NEGOEX) security mechanism on Windows, enabled by default on supported Windows client and server versions.
A critical, potentially wormable, unauthenticated remote code execution vulnerability in Windows Spnego Extended Negotiation (NEGOEX) caused by a heap-based buffer overflow, enabling remote code execution via specially crafted messages (noted as executing with elevated privileges).
A wormable buffer overflow vulnerability in Windows SPNEGO Extended Negotiation security mechanism, allowing remote code execution by unauthorized attackers with no user interaction required.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.