CVE-2025-59188Sensitive Information Exposure in Microsoft Windows Server 2012

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 79.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

NVDmicrosoft/windows< 10.0.14393.8519+5
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25722
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8519
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.7919
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4294

🔴Vulnerability Details

2
GHSA
GHSA-4r8v-w9wf-3vgm: Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally2025-10-14
CVEList
Microsoft Failover Cluster Information Disclosure Vulnerability2025-10-14

📋Vendor Advisories

1
Microsoft
Microsoft Failover Cluster Information Disclosure Vulnerability2025-10-14
CVE-2025-59188 — Sensitive Information Exposure | cvebase