CVE-2025-55683Sensitive Information Exposure in Microsoft Windows Server 2016

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 78.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDmicrosoft/windows< 10.0.14393.8519+4
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8519
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.7919
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4294
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.6899

🔴Vulnerability Details

2
CVEList
Windows Kernel Information Disclosure Vulnerability2025-10-14
GHSA
GHSA-fwgq-v3hj-v285: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally2025-10-14

📋Vendor Advisories

1
Microsoft
Windows Kernel Information Disclosure Vulnerability2025-10-14

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14
CVE-2025-55683 — Sensitive Information Exposure | cvebase