Description
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages5 packages
🔴Vulnerability Details
2CVEListMicrosoft Failover Cluster Virtual Driver Information Disclosure Vulnerability↗2025-10-14 ▶ GHSAGHSA-97pg-5p27-4jfg: Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose info↗2025-10-14 ▶ 📋Vendor Advisories
1MicrosoftMicrosoft Failover Cluster Virtual Driver Information Disclosure Vulnerability↗2025-10-14 ▶ 🕵️Threat Intelligence
1BleepingcomputerMicrosoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws↗2025-10-14 ▶