KB5089899 is the SQL Server 2025 CU4 + GDR security update for build 17.0.4040.1. Microsoft says the release contains fixes and resolves vulnerabilities, and the published details point to one verified fix in Integration Services.

The update applies to SQL Server product version 17.0.4040.1, with file version 2025.170.4040.1.

Improvements and fixes

This release includes 1 verified fix.

Integration Services

Microsoft says the fix addresses an XML external entity (XXE) issue in the Web Service Task on Windows Integration Services. According to the release notes, the issue could allow an attacker to read arbitrary files from the local file system or trigger a denial-of-service (DoS) attack.

The bug reference listed for this item is 5178546.

Known issues

Microsoft documents one known issue for this update:

  • Linked server queries that use MSDASQL can fail with error 7416 when they specify a provider string (@provstr). The reported message is: Msg 7416, Level 16 Access to the remote server is denied because no login-mapping exists. Microsoft says a stricter connection validation check in the Database Engine can reject some linked server configurations that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider, even when earlier builds allowed them.

Microsoft links to a separate article for more information and workarounds. If this issue is no longer shown in the source later, that removal alone would not prove the problem is resolved.

Official source