cbcvebase.
CVE-2025-59258
published 2025-10-14

CVE-2025-59258: Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

Affected

19 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.257226.2.9200.25722
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.228246.3.9600.22824
microsoftwindows_server_2016<= 10.0.14393.8519
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.851910.0.14393.8519
microsoftwindows_server_2019< 10.0.17763.791910.0.17763.7919
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.791910.0.17763.7919
microsoftwindows_server_2022< 10.0.20348.429410.0.20348.4294
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.429410.0.20348.4294
microsoftwindows_server_2022_23h2< 10.0.25398.191310.0.25398.1913
microsoftwindows_server_2025<= 10.0.26100.6899
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.689910.0.26100.6899
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025