Information Disclosure in Windows High Availability Services by Microsoft
CVE-2025-59184

5.5MEDIUM

What is CVE-2025-59184?

An information disclosure vulnerability exists in Windows High Availability Services, allowing an authorized attacker to access sensitive data locally. This flaw may result in unauthorized information exposure, potentially harming system confidentiality. Users of Windows High Availability Services should ensure they are aware of this vulnerability to safeguard their data.

Affected Version(s)

Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.8519

Windows Server 2016 x64-based Systems 10.0.14393.0 < 10.0.14393.8519

Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.7919

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59184 : Information Disclosure in Windows High Availability Services by Microsoft