CVE-2025-59284Sensitive Information Exposure in Microsoft Windows 11 Version 22h2

Severity
5.5MEDIUMNVD
CNA3.3
EPSS
0.0%
top 89.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages11 packages

NVDmicrosoft/windows< 10.0.26100.6899
NVDmicrosoft/windows_11_22h2< 10.0.22621.6060
NVDmicrosoft/windows_11_23h2< 10.0.22631.6060
NVDmicrosoft/windows_11_24h2< 10.0.26100.6899
NVDmicrosoft/windows_11_25h2< 10.0.26200.6899

🔴Vulnerability Details

2
CVEList
Windows NTLM Spoofing Vulnerability2025-10-14
GHSA
GHSA-r7mr-x282-4wjx: Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally2025-10-14

📋Vendor Advisories

1
Microsoft
Windows NTLM Spoofing Vulnerability2025-10-14
CVE-2025-59284 — Sensitive Information Exposure | cvebase