5.5
CVE-2025-59260
- EPSS 0.07%
- Veröffentlicht 14.10.2025 17:01:44
- Zuletzt bearbeitet 20.10.2025 19:50:05
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2016 Version <= 10.0.14393.8519
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.7919
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.4294
Microsoft ≫ Windows Server 2022 23h2 Version < 10.0.25398.1913
Microsoft ≫ Windows Server 2025 Version <= 10.0.26100.6899
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.222 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.