CVE-2025-12743Disclosure

MEDIUMCVSS 6.0 · MEDIUM

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connection name, which is a reserved internal name for Looker's internal MySQL database. The schemas parameter is vulnerable to SQL injection, enabling attackers to manipulate SELECT queries that are constructed and executed against the internal MySQL database. This vulnerability allows users with developer permissions to extract data from Looker's internal MySQL database. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded as soon as possible. This vulnerability has been patched in all supported versions of Self-hosted. The versions below have all been updated to protect against this vulnerability. You can download these versions at the Looker download page https://download.looker.com/ : * 24.12.106 * 24.18.198+ * 25.0.75 * 25.6.63+ * 25.8.45+ * 25.10.33+ * 25.12.1+ * 25.14+

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-02-04); latest day: 4
  • 11 total mentions across 2 days

Deep dive

Activity timeline11 mentions / 2d
02457Mentions · 2026-02-04: 7Mentions · 2026-02-05: 4Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-04: 2Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 202-0402-05
Signal classification4 categories
Disclosure
763.6%
General
218.2%
Patch
19.1%
Active Exploitation
19.1%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-047
Disclosure5General1Patch1
2026-02-054
Active Exploitation1Disclosure2General1
Full discourse11 posts
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The article announces major vulnerabilities in Google Looker, specifically CVE‑2025‑12743, that pose risks to self‑hosted deployments.

    02061520
    192.8K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月4日〜5日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、VMware ESXiの脆弱性がランサムウェア攻撃に悪用されていると警告(CVE-2025-22225) https://www.bleepingcomputer.com/news/security/cisa-vmware-esxi-flaw-now-exploited-in-ransomware-attacks/ ・React2Shellを悪用した攻撃が進行中、クリプトマイナーとリバースシェルを拡散(CVE-2025-55182) https://www.securityweek.com/cryptominers-reverse-shells-dropped-in-recent-react2shell-attacks/ ・Google Lookerに複数の重大な脆弱性、セルフホスト型環境が危険にさらされる(CVE-2025-12743) https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/ ・5年前のGitLabの脆弱性が攻撃に悪用される CISAが警告(CVE-2021-39935) https://www.bleepingcomputer.com/news/security/cisa-warns-of-five-year-old-gitlab-flaw-exploited-in-attacks/ ・n8nの重大な脆弱性とエクスプロイトが公開される(CVE-2026-25049) https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/ <マルウェア・その他脅威> ・EDRキラー、EnCaseの署名付きカーネルドライバーを使用してセキュリティを無効化 https://www.bleepingcomputer.com/news/security/edr-killer-tool-uses-signed-kernel-driver-from-forensic-software/ <ランサムウェア> ・ランサムウェアグループ「DragonForce」、カルテルモデル推進で「ゴッドファーザー」さながらに https://www.darkreading.com/cyber-risk/ransomware-gang-full-godfather-cartel ・Nitrogenランサムウェアは実行犯でも復号不可能 身代金支払いは無駄 https://www.theregister.com/2026/02/04/nitrogen_ransomware_broken_decryptor/ <データ侵害/サイバー犯罪> ・大規模な情報漏洩は事実か? メキシコ政府は機微なデータの漏洩を否認 https://www.darkreading.com/cyberattacks-data-breaches/big-breach-or-nada-de-nada-mexican-govt-faces-leak-allegations ・AIを使ったクラウド侵害、公開状態のAWS認証情報から8分で管理者権限を獲得 https://hackread.com/8-minute-takeover-ai-hijack-cloud-access/ ・ShinyHunters、米ハーバード大とペンシルベニア大の内部情報とみられるデータを公開 https://techcrunch.com/2026/02/04/hackers-publish-personal-information-stolen-during-harvard-upenn-data-breaches/ ・ハッカーがnginxサーバーを侵害、ユーザートラフィックをリダイレクト https://www.bleepingcomputer.com/news/security/hackers-compromise-nginx-servers-to-redirect-user-traffic/ <サイバー戦/APT/国家型アクター/地政学関連> ・欧州議会議員、ITサービスの米国依存に警鐘 「EUはマイクロソフトで動いている」 https://www.theregister.com/2026/02/04/eu_foss_fears/ ・ロシアの偵察衛星、EUの複数の通信衛星を傍受 https://arstechnica.com/space/2026/02/russian-spy-satellites-have-intercepted-eu-communications-satellites/ ・米国が2025年にサイバー兵器を攻撃に使用 イランの防空網を混乱させる目的で https://therecord.media/iran-nuclear-cyber-strikes-us ・中国のAmaranth-Dragon、偵察活動でWinRARの脆弱性を悪用(CVE-2025-8088) https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ダークウェブの麻薬市場「Incognito Market」の運営者に拘禁30年の判決 https://www.bleepingcomputer.com/news/security/taiwanese-man-gets-30-years-for-operating-dark-web-drug-market/ <リサーチ/攻撃手法/TTP> ・Windowsのスクリーンセーバーファイル、攻撃者がマルウェアやRMMツールの配布に利用 https://www.darkreading.com/application-security/attackers-use-screensavers-drop-malware-rmm-tools <政府/政策> ・エストニア政府、マイクロソフトへ移行しつつも欧州の代替サービスを模索中 https://www.theregister.com/2026/02/04/estonia_hedges_its_bets_on/ ・米上院議員、ICEデモ参加者に関するデータベースの有無を政府に問う https://arstechnica.com/tech-policy/2026/02/capture-it-all-ice-urged-to-explain-memo-about-collecting-info-on-protesters/ <その他> ・マイクロソフト、Windows 11にネイティブなSysmon機能を導入予定 https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-native-windows-11-sysmon-security-monitoring/

    Post summary

    The listed news items collectively confirm that several CVEs—including VMware ESXi, GitLab, and WinRAR—are actively exploited in the wild, with reports from CISA and other security outlets.

    01020353
    1.2K followersView on X
  • キタきつね@foxbook
    Disclosure

    Google Looker に重大な脆弱性が発見され、セルフホスト型のデプロイメントが危険にさらされる Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk #HelpNetSecurity (Feb 4) https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/

    Post summary

    Google Looker has identified major vulnerabilities that threaten self‑hosted deployments, but the announcement lacks details on PoC, exploitation, or remediation.

    00011237
    4.7K followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk - https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/ - @TenableSecurity #CVE #CyberSecurity #CyberSecurityNews

    Post summary

    The post announces major vulnerabilities affecting self‑hosted Google Looker deployments, but does not provide technical details, exploit code, or mitigation information.

    00020367
    60.0K followersView on X
  • ProbablyPwned@probablypwned
    Disclosure

    Tenable discloses critical 'LookOut' vulnerabilities in Google Looker, enabling remote code execution and full database theft. Over 60,000 self-hosted deployments at risk. Read more: https://www.probablypwned.com/article/google-looker-lookout-vulnerabilities-cve-2025-12743-rce-database

    Post summary

    Tenable discloses critical Looker LookOut RCE vulnerabilities affecting over 60,000 self‑hosted deployments, highlighting remote code execution and database theft capabilities.

    1000045
    16 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    紛らわしい名称... 『We have collectively dubbed both vulnerabilities as “LookOut.”』 CVE-2025-12743 LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem) https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout

    Post summary

    The post announces CVE‑2025‑12743, naming it “LookOut,” and notes it enables RCE and internal access in Looker, but it provides no PoC, exploit code, or patch information.

    00010395
    6.7K followersView on X
  • DCI CyberSec News@DCICyberSecNews
    General

    Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/ --via Cyware Social

    Post summary

    The article reports major vulnerabilities in Google Looker that threaten self‑hosted deployments, but it offers no further technical details, exploit evidence, or remediation guidance.

    0000053
    2.1K followersView on X
  • Jeff Whitehead@Whitehead4Jeff
    General

    Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/

    Post summary

    The article announces major vulnerabilities in Google Looker for self-hosted deployments but provides no additional technical details, PoC, or evidence of exploitation.

    0000035
    185 followersView on X
  • CivicRiskHQ@CivicRisk
    Patch

    5. The @civicriskhq "LookOut" Defense Checklist: ✅ Patch Immediately: Google has released fixes for the "LookOut" vulnerabilities (CVE-2025-12743). If you haven't updated in the last 24 hours, you are exposed. ✅ Audit Service Accounts: Looker often has high-level permissions to your databases. Limit its "Write" access to only what is strictly necessary. ✅ Monitor Internal Traffic: Look for anomalies where your BI tools are attempting to connect to internal management ports they shouldn't be touching. Your analytics tool should show you the future, not give it away to hackers. 🛡️ Bookmark this before your next data sync. END… Follow for more

    Post summary

    The post highlights that Google has issued a patch for CVE‑2025‑12743 and urges users to apply it immediately, without providing technical details or exploit evidence.

    0000028
    51 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 “LookOut” flaws in Google Looker could enable self-hosted takeover and data access Tenable disclosed two “LookOut” vulnerabilities tied to CVE-2025-12743 that can expose secrets and create a path to compromise self-hosted Looker instances, potentially leading to system takeover or access to sensitive BI-connected corporate data; Google says hosted Looker is already mitigated while self-hosted customers must upgrade to patched releases. This matters because Looker often aggregates “crown-jewel” datasets across many backends, so one weak self-hosted node can become a high-blast-radius pivot. 🎯 Target: Global/Enterprises (Self-hosted Google Looker) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/

    Post summary

    Tenable disclosed CVE-2025-12743 LookOut vulnerabilities that can lead to takeover of self‑hosted Google Looker instances; Google advises upgrading to patched releases.

    0000044
    192 followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    Major vulnerabilities found in Google Looker, putting self-hosted deployments at risk: Researchers at Tenable have disclosed two vulnerabilities, collectively referred to as “LookOut,” affecting Google Looker. Because the business intelligence platform… https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/?utm_source=dlvr.it&utm_medium=twitter https://t.co/v04LsFgBlE

    Post summary

    Researchers Tenable have disclosed two vulnerabilities in self‑hosted Google Looker deployments, known as LookOut, but the tweet provides no technical details, PoC, or evidence of active exploitation.

    0000043
    2.2K followersView on X

Explore more