Information Disclosure Vulnerability in Windows Smart Card Reader by Microsoft
CVE-2025-21312

2.4LOW

Key Information:

Summary

An information disclosure vulnerability exists in the Windows Smart Card Reader when it improperly handles certain requests. This could allow an attacker to obtain sensitive information that is intended to be protected. The vulnerability arises from insufficient validation of data, and it is essential for users to apply relevant security updates to mitigate potential risks.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20890

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7699

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.6775

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.