Information Disclosure Vulnerability in Microsoft Failover Cluster
CVE-2025-59188

5.5MEDIUM

What is CVE-2025-59188?

An information disclosure vulnerability exists in Microsoft Failover Cluster, which may allow an authorized attacker to locally disclose sensitive information. This issue can lead to unauthorized data access, exposing critical information that could be utilized for further attacks. It is crucial for organizations using Windows Failover Cluster to apply appropriate security measures and ensure that their systems are updated to mitigate any potential risks associated with this vulnerability.

Affected Version(s)

Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.25722

Windows Server 2012 R2 (Server Core installation) x64-based Systems 6.3.9600.0 < 6.3.9600.22824

Windows Server 2012 R2 x64-based Systems 6.3.9600.0 < 6.3.9600.22824

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59188 : Information Disclosure Vulnerability in Microsoft Failover Cluster