Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2025-1218 and is rated Low severity with a CVSS score of 3.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can crash the process.