CVE-2025-53156Sensitive Information Exposure in Microsoft Windows 11 Version 24h2

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDmicrosoft/windows< 10.0.25398.1791+1
NVDmicrosoft/windows_11_24h2< 10.0.26100.4851
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.4946
CVEListV5microsoft/windows_11_version_24h210.0.26100.010.0.26100.4946

🔴Vulnerability Details

2
CVEList
Windows Storage Port Driver Information Disclosure Vulnerability2025-08-12
GHSA
GHSA-2mc5-3c8c-rg8r: Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally2025-08-12

📋Vendor Advisories

2
Microsoft
Windows Storage Port Driver Information Disclosure Vulnerability2025-08-12
Microsoft
wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()2024-12-10

🕵️Threat Intelligence

5
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review | Qualys2025-08-12
Talos
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities2025-08-12
Talos
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilities2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review2025-08-12
CVE-2025-53156 — Sensitive Information Exposure | cvebase