CVE-2025-59258Log File Information Exposure in Microsoft Windows Server 2012

Severity
6.2MEDIUMNVD
EPSS
0.1%
top 79.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.5 | Impact: 3.6

Affected Packages7 packages

NVDmicrosoft/windows< 10.0.17763.7919+4
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25722
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8519
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.7919
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4294

🔴Vulnerability Details

2
CVEList
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability2025-10-14
GHSA
GHSA-fp3r-vj8x-58ww: Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information local2025-10-14

📋Vendor Advisories

1
Microsoft
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability2025-10-14
CVE-2025-59258 — Log File Information Exposure | cvebase